Tue Apr 21 06:25:06 MDT 2020 06:25:06 up 56 days, 10:53, 1 user, load average: 0.40, 0.27, 0.27 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 56days 1:16m 2.53s /usr/bin/lxsession -s LXDE-pi -e LXDE 196.219.162.50 - - [21/Apr/2020:13:02:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 83.110.104.31 - - [21/Apr/2020:13:20:27 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC BOTNET" 83.110.104.31 - - [21/Apr/2020:13:20:28 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.243.132.250 - - [21/Apr/2020:13:28:55 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 195.67.155.98 - - [21/Apr/2020:13:46:56 +0000] "GET / HTTP/1.1" 400 0 "" "" 94.180.150.27 - - [21/Apr/2020:13:57:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 103.243.82.254 - - [21/Apr/2020:14:02:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 49.236.213.248 - - [21/Apr/2020:14:10:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 46.101.171.183 - - [21/Apr/2020:14:30:05 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 200.33.152.1 - - [21/Apr/2020:14:37:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 217.127.105.21 - - [21/Apr/2020:17:43:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 217.127.105.21 - - [21/Apr/2020:17:43:50 +0000] "GET /dana-na/auth/url_default/welcome.cgi HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 34.220.240.213 - - [21/Apr/2020:18:37:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 42.115.8.136 - - [21/Apr/2020:18:57:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 92.118.161.57 - - [21/Apr/2020:19:11:21 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 179.125.107.169 - - [21/Apr/2020:20:03:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 138.36.2.3 - - [21/Apr/2020:21:35:30 +0000] "GET / HTTP/1.1" 400 0 "" "" 51.68.225.51 - - [21/Apr/2020:21:52:23 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 5.188.210.101 - - [21/Apr/2020:21:55:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [21/Apr/2020:21:55:21 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [21/Apr/2020:21:55:29 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [21/Apr/2020:21:57:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [21/Apr/2020:21:57:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [21/Apr/2020:21:57:17 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [21/Apr/2020:21:58:58 +0000] "GET /echo.php HTTP/1.1" 404 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 59.125.226.69 - - [22/Apr/2020:01:47:43 +0000] "GET / HTTP/1.1" 400 0 "" "" 162.243.133.13 - - [22/Apr/2020:02:47:47 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 201.28.114.19 - - [22/Apr/2020:03:24:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 191.241.174.29 - - [22/Apr/2020:03:26:47 +0000] "GET / HTTP/1.1" 400 0 "" "" 46.233.40.185 - - [22/Apr/2020:03:59:42 +0000] "GET / HTTP/1.1" 400 0 "" "" 52.16.13.13 - - [22/Apr/2020:05:29:00 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 52.16.13.13 - - [22/Apr/2020:05:29:04 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 52.16.13.13 - - [22/Apr/2020:05:29:04 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 52.16.13.13 - - [22/Apr/2020:05:29:05 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 52.16.13.13 - - [22/Apr/2020:05:29:05 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 52.16.13.13 - - [22/Apr/2020:05:29:05 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 52.16.13.13 - - [22/Apr/2020:05:29:06 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 52.16.13.13 - - [22/Apr/2020:05:29:06 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 52.16.13.13 - - [22/Apr/2020:05:29:06 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 52.16.13.13 - - [22/Apr/2020:05:29:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.162.119.197 - - [22/Apr/2020:06:33:12 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 94.140.114.17 - - [22/Apr/2020:06:54:00 +0000] "GET / HTTP/1.0" 200 25000 "" "Pandalytics/1.0 (https://domainsbot.com/pandalytics/)" 170.233.71.169 - - [22/Apr/2020:07:29:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 177.33.251.50 - - [22/Apr/2020:08:24:00 +0000] "GET / HTTP/1.1" 400 0 "" "" 24.41.253.2 - - [22/Apr/2020:08:24:11 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC BOTNET" 24.41.253.2 - - [22/Apr/2020:08:24:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 24.41.253.2 - - [22/Apr/2020:08:24:12 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC BOTNET" 24.41.253.2 - - [22/Apr/2020:08:24:13 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 192.241.203.163 - - [22/Apr/2020:08:29:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 223.149.6.45 - - [22/Apr/2020:08:49:48 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 187.95.114.237 - - [22/Apr/2020:09:01:34 +0000] "GET / HTTP/1.1" 400 0 "" "" 119.42.103.222 - - [22/Apr/2020:09:42:43 +0000] "GET / HTTP/1.1" 400 0 "" "" Wed Apr 22 06:25:06 MDT 2020 06:25:06 up 57 days, 10:53, 1 user, load average: 0.39, 0.23, 0.22 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 57days 1:17m 2.53s /usr/bin/lxsession -s LXDE-pi -e LXDE