Wed Apr 29 06:25:05 MDT 2020 06:25:05 up 64 days, 10:53, 1 user, load average: 0.21, 0.22, 0.25 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 64days 1:21m 2.65s /usr/bin/lxsession -s LXDE-pi -e LXDE 35.153.211.189 - - [29/Apr/2020:13:16:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.156.246.199 - - [29/Apr/2020:13:34:25 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.128.41.50 - - [29/Apr/2020:13:35:01 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Java/1.8.0_131" 61.93.228.52 - - [29/Apr/2020:13:39:13 +0000] "GET / HTTP/1.1" 400 0 "" "" 203.188.241.211 - - [29/Apr/2020:14:24:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 136.169.224.65 - - [29/Apr/2020:14:38:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.138.138 - - [29/Apr/2020:15:04:02 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 69.171.192.58 - - [29/Apr/2020:15:16:15 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 69.171.192.58 - - [29/Apr/2020:15:16:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 196.52.43.124 - - [29/Apr/2020:17:25:52 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3602.2 Safari/537.36" 65.36.10.248 - - [29/Apr/2020:17:40:37 +0000] "POST /boaform/admin/formPing HTTP/1.1" 400 0 "" "polaris botnet" 65.36.10.248 - - [29/Apr/2020:17:40:37 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.153.196.245 - - [29/Apr/2020:17:53:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 134.169.109.83 - - [29/Apr/2020:18:49:57 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 193.118.53.210 - - [29/Apr/2020:18:58:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 45.173.76.112 - - [29/Apr/2020:19:53:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 187.202.155.109 - - [29/Apr/2020:21:33:57 +0000] "GET / HTTP/1.1" 400 0 "" "" 80.181.213.59 - - [29/Apr/2020:22:22:16 +0000] "GET / HTTP/1.1" 400 0 "" "" 80.181.213.59 - - [29/Apr/2020:22:22:35 +0000] "GET / HTTP/1.1" 400 0 "" "" 80.181.213.59 - - [29/Apr/2020:22:22:41 +0000] "GET / HTTP/1.1" 400 0 "" "" 80.181.213.59 - - [29/Apr/2020:22:23:01 +0000] "GET / HTTP/1.1" 400 0 "" "" 172.105.89.161 - - [30/Apr/2020:00:27:47 +0000] "GET /0bef HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.116 Safari/537.36" 117.239.149.94 - - [30/Apr/2020:00:44:36 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 94.241.131.60 - - [30/Apr/2020:01:28:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.136.15 - - [30/Apr/2020:03:44:50 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 49.232.18.72 - - [30/Apr/2020:05:01:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 49.232.18.72 - - [30/Apr/2020:05:02:01 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.232.18.72 - - [30/Apr/2020:05:02:01 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.232.18.72 - - [30/Apr/2020:05:02:02 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.232.18.72 - - [30/Apr/2020:05:02:03 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.232.18.72 - - [30/Apr/2020:05:02:03 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.232.18.72 - - [30/Apr/2020:05:02:04 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.232.18.72 - - [30/Apr/2020:05:02:05 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.232.18.72 - - [30/Apr/2020:05:02:05 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.232.18.72 - - [30/Apr/2020:05:02:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 193.118.53.202 - - [30/Apr/2020:05:19:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 108.226.111.106 - - [30/Apr/2020:05:22:31 +0000] "GET / HTTP/1.1" 400 0 "" "" 62.173.152.144 - - [30/Apr/2020:05:35:09 +0000] "GET / HTTP/1.0" 200 25000 "" "sysscan/1.0 (https://github.com/robertdavidgraham/sysscan)" 86.124.71.186 - - [30/Apr/2020:07:27:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 14.161.32.122 - - [30/Apr/2020:07:42:02 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC BOTNET" 14.161.32.122 - - [30/Apr/2020:07:42:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 78.188.41.178 - - [30/Apr/2020:08:31:15 +0000] "POST /boaform/admin/formPing HTTP/1.1" 400 0 "" "polaris botnet" 78.188.41.178 - - [30/Apr/2020:08:31:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 177.45.188.50 - - [30/Apr/2020:08:38:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 31.134.16.13 - - [30/Apr/2020:09:00:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 113.125.105.237 - - [30/Apr/2020:09:49:22 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 83.97.20.21 - - [30/Apr/2020:10:12:38 +0000] "GET / HTTP/1.0" 200 25000 "" "" 178.206.231.54 - - [30/Apr/2020:11:19:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 200.113.54.42 - - [30/Apr/2020:11:44:56 +0000] "GET / HTTP/1.1" 400 0 "" "" 45.238.244.8 - - [30/Apr/2020:11:54:12 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 45.238.244.8 - - [30/Apr/2020:11:54:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 95.234.236.101 - - [30/Apr/2020:12:19:01 +0000] "GET / HTTP/1.1" 400 0 "" "" Thu Apr 30 06:25:06 MDT 2020 06:25:06 up 65 days, 10:53, 1 user, load average: 0.29, 0.25, 0.24 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 65days 1:22m 2.65s /usr/bin/lxsession -s LXDE-pi -e LXDE