Mon Apr 27 06:25:31 MDT 2020 06:25:31 up 62 days, 10:54, 1 user, load average: 2.06, 0.66, 0.39 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 62days 1:20m 2.53s /usr/bin/lxsession -s LXDE-pi -e LXDE 159.65.187.1 - - [27/Apr/2020:12:27:26 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 209.141.41.128 - - [27/Apr/2020:12:59:48 +0000] "GET /axis2/services/Cat/exec?cmd=whoami HTTP/1.1" 404 0 "" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)" 203.205.27.63 - - [27/Apr/2020:13:07:13 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 203.205.27.63 - - [27/Apr/2020:13:07:14 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.240.205.34 - - [27/Apr/2020:13:29:40 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.153.196.245 - - [27/Apr/2020:15:06:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.243.132.7 - - [27/Apr/2020:15:24:44 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 176.193.198.67 - - [27/Apr/2020:15:55:45 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 64.225.110.177 - - [27/Apr/2020:15:58:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_4) AppleWebKit/603.1.30 (KHTML, like Gecko) Version/10.1 Safari/603.1.30" 81.30.144.119 - - [27/Apr/2020:16:09:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 167.71.209.144 - - [27/Apr/2020:18:22:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; en) Opera 8.50" 128.199.246.207 - - [27/Apr/2020:18:35:04 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 162.243.131.51 - - [27/Apr/2020:18:47:58 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 83.97.20.21 - - [27/Apr/2020:19:22:31 +0000] "GET / HTTP/1.0" 200 25000 "" "" 105.216.62.119 - - [27/Apr/2020:20:06:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 116.72.133.187 - - [27/Apr/2020:20:52:18 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 116.72.133.187 - - [27/Apr/2020:20:52:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 209.141.41.128 - - [27/Apr/2020:21:17:49 +0000] "GET /axis2/services/Cat/exec?cmd=whoami HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible, MSIE 10.0, Windows NT, DigExt)" 92.63.194.30 - - [27/Apr/2020:21:26:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 176.43.128.2 - - [27/Apr/2020:21:42:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 177.189.79.55 - - [27/Apr/2020:23:34:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 162.209.162.251 - - [27/Apr/2020:23:57:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 14.254.171.90 - - [28/Apr/2020:01:23:38 +0000] "GET / HTTP/1.1" 400 0 "" "" 130.61.218.121 - - [28/Apr/2020:01:31:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 130.61.218.121 - - [28/Apr/2020:01:31:22 +0000] "GET /home.asp HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 130.61.218.121 - - [28/Apr/2020:01:31:22 +0000] "GET /login.cgi?uri= HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 130.61.218.121 - - [28/Apr/2020:01:31:23 +0000] "GET /vpn/index.html HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 130.61.218.121 - - [28/Apr/2020:01:31:23 +0000] "GET /cgi-bin/luci HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 130.61.218.121 - - [28/Apr/2020:01:31:23 +0000] "GET /dana-na/auth/url_default/welcome.cgi HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 130.61.218.121 - - [28/Apr/2020:01:31:24 +0000] "GET /remote/login?lang=en HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 130.61.218.121 - - [28/Apr/2020:01:31:24 +0000] "GET /index.asp HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 130.61.218.121 - - [28/Apr/2020:01:31:25 +0000] "GET /htmlV/welcomeMain.htm HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 96.127.169.2 - - [28/Apr/2020:02:07:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 77.35.178.122 - - [28/Apr/2020:02:17:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 117.50.40.205 - - [28/Apr/2020:03:31:34 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 117.50.40.205 - - [28/Apr/2020:03:31:34 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 222.237.81.201 - - [28/Apr/2020:03:45:19 +0000] "GET / HTTP/1.1" 400 0 "" "" 192.241.234.142 - - [28/Apr/2020:04:16:42 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 167.114.39.181 - - [28/Apr/2020:06:24:45 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 178.128.222.196 - - [28/Apr/2020:07:05:40 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 125.25.54.169 - - [28/Apr/2020:07:29:10 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 125.25.54.169 - - [28/Apr/2020:07:29:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 139.162.119.197 - - [28/Apr/2020:07:53:37 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 117.157.15.27 - - [28/Apr/2020:08:11:36 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 117.157.15.27 - - [28/Apr/2020:08:11:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.46.40.237 - - [28/Apr/2020:08:44:29 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 125.166.185.224 - - [28/Apr/2020:08:58:31 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 192.241.235.230 - - [28/Apr/2020:10:28:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 111.125.241.74 - - [28/Apr/2020:10:32:37 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox&curpath=/¤tsetting.htm=1 HTTP/1.1" 400 0 "" "Mozilla/5.0" 111.125.241.74 - - [28/Apr/2020:10:32:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 1.53.252.17 - - [28/Apr/2020:11:55:09 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 161.35.43.230 - - [28/Apr/2020:12:04:46 +0000] "GET /news.php?type=0&time=10:17:27 HTTP/1.1" 404 0 "" "Mozilla/5.0 (iPhone; CPU iPhone OS 9_3 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13E188a Safari/601.1" Tue Apr 28 06:25:06 MDT 2020 06:25:07 up 63 days, 10:53, 1 user, load average: 0.28, 0.22, 0.20 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 63days 1:20m 2.53s /usr/bin/lxsession -s LXDE-pi -e LXDE