Sun May 10 06:25:13 MDT 2020
06:25:13 up 75 days, 10:53, 1 user, load average: 0.63, 0.34, 0.29
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
pi tty7 :0 24Feb20 75days 1:28m 2.81s /usr/bin/lxsession -s LXDE-pi -e LXDE
106.104.137.36 - - [10/May/2020:12:33:06 +0000] "GET / HTTP/1.1" 400 0 "" ""
27.69.160.134 - - [10/May/2020:15:52:12 +0000] "GET /setup.cgi HTTP/1.1" 400 0 "" ""
27.69.160.134 - - [10/May/2020:15:52:13 +0000] "GET /sess-bin/login_session.cgi HTTP/1.1" 400 0 "" ""
27.69.160.134 - - [10/May/2020:15:52:13 +0000] "GET /sess-bin/login_session.cgi HTTP/1.1" 400 0 "" ""
27.69.160.134 - - [10/May/2020:15:52:14 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd"
27.69.160.134 - - [10/May/2020:15:52:14 +0000] "GET /sess-bin/login_session.cgi HTTP/1.1" 400 0 "" ""
27.69.160.134 - - [10/May/2020:15:52:16 +0000] "GET /shell?/bin/busybox+ABCD HTTP/1.1" 400 0 "" "Abcd"
27.69.160.134 - - [10/May/2020:15:52:50 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd"
27.69.160.134 - - [10/May/2020:15:52:50 +0000] "POST /doLogin HTTP/1.1" 404 0 "" "Abcd"
27.69.160.134 - - [10/May/2020:15:52:51 +0000] "GET /setup.cgi HTTP/1.1" 400 0 "" ""
27.69.160.134 - - [10/May/2020:15:53:19 +0000] "UNKNOWN UNKNOWN" 408 0 "" ""
94.140.114.17 - - [10/May/2020:16:04:40 +0000] "GET / HTTP/1.0" 200 25000 "" "Pandalytics/1.0 (https://domainsbot.com/pandalytics/)"
185.216.140.6 - - [10/May/2020:16:12:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x"
221.208.194.224 - - [10/May/2020:16:53:34 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)"
139.9.200.66 - - [10/May/2020:17:21:16 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
139.9.200.66 - - [10/May/2020:17:21:16 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0"
167.99.6.42 - - [10/May/2020:17:36:22 +0000] "GET / HTTP/1.1" 200 25000 "" "PycURL/7.43.0.2 libcurl/7.64.0 GnuTLS/3.6.7 zlib/1.2.11 libidn2/2.0.5 libpsl/0.20.2 (+libidn2/2.0.5) libssh2/1.8.0 nghttp2/1.36.0 librtmp/2.3"
47.92.6.236 - - [10/May/2020:17:40:37 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)"
103.199.114.91 - - [10/May/2020:18:57:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
195.54.160.121 - - [10/May/2020:19:09:40 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
195.54.160.121 - - [10/May/2020:19:15:27 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
195.54.160.121 - - [10/May/2020:19:15:27 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
195.54.160.121 - - [10/May/2020:19:25:35 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
80.147.192.138 - - [10/May/2020:19:26:45 +0000] "GET / HTTP/1.1" 400 0 "" ""
177.53.104.2 - - [10/May/2020:19:35:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
78.188.113.184 - - [10/May/2020:20:19:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36"
81.93.196.138 - - [10/May/2020:20:56:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36"
195.54.160.121 - - [10/May/2020:21:21:47 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
45.83.66.100 - - [10/May/2020:21:29:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0"
188.136.168.204 - - [10/May/2020:23:01:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
190.92.4.231 - - [11/May/2020:01:00:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
82.53.199.53 - - [11/May/2020:01:49:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
193.42.99.162 - - [11/May/2020:01:51:42 +0000] "UNKNOWN UNKNOWN" 0 0 "" ""
193.42.99.162 - - [11/May/2020:01:51:42 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" ""
172.105.89.161 - - [11/May/2020:01:54:33 +0000] "GET /0bef HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.116 Safari/537.36"
195.54.160.121 - - [11/May/2020:02:12:07 +0000] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
195.54.160.121 - - [11/May/2020:03:10:09 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.243.138.64 - - [11/May/2020:04:42:59 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x"
162.243.136.230 - - [11/May/2020:05:39:33 +0000] "GET /manager/text/list HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x"
41.39.32.48 - - [11/May/2020:07:56:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" ""
41.39.32.48 - - [11/May/2020:07:57:54 +0000] "UNKNOWN UNKNOWN" 408 0 "" ""
41.39.32.48 - - [11/May/2020:07:57:59 +0000] "UNKNOWN UNKNOWN" 408 0 "" ""
47.106.74.12 - - [11/May/2020:08:37:05 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0"
47.106.74.12 - - [11/May/2020:08:37:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" ""
195.54.160.121 - - [11/May/2020:08:37:48 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
109.72.196.223 - - [11/May/2020:08:40:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
195.54.160.121 - - [11/May/2020:08:47:10 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
195.54.160.121 - - [11/May/2020:08:47:10 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
197.220.196.199 - - [11/May/2020:08:51:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
195.54.160.121 - - [11/May/2020:09:01:11 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
52.172.52.205 - - [11/May/2020:09:02:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" ""
52.172.52.205 - - [11/May/2020:09:02:38 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
52.172.52.205 - - [11/May/2020:09:02:39 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
52.172.52.205 - - [11/May/2020:09:02:39 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
52.172.52.205 - - [11/May/2020:09:02:40 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
52.172.52.205 - - [11/May/2020:09:02:40 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
52.172.52.205 - - [11/May/2020:09:02:41 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
52.172.52.205 - - [11/May/2020:09:02:41 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
52.172.52.205 - - [11/May/2020:09:02:42 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
52.172.52.205 - - [11/May/2020:09:02:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)"
193.70.13.15 - - [11/May/2020:09:34:52 +0000] "HEAD /lPn3 HTTP/1.1" 404 0 "" "Mozilla/5.0 (X11; CrOS i686 4319.74.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.57 Safari/537.36"
80.99.129.51 - - [11/May/2020:10:23:37 +0000] "GET / HTTP/1.1" 400 0 "" ""
143.255.6.78 - - [11/May/2020:10:30:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36"
68.14.53.27 - - [11/May/2020:11:40:30 +0000] "UNKNOWN UNKNOWN" 400 0 "" ""
68.14.53.27 - - [11/May/2020:11:40:30 +0000] "GET / HTTP/1.1" 200 25000 "" ""
195.54.160.121 - - [11/May/2020:11:47:36 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.245.52.231 - - [11/May/2020:11:50:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" ""
172.245.52.231 - - [11/May/2020:11:50:28 +0000] "UNKNOWN UNKNOWN" 400 0 "" ""
Mon May 11 06:25:06 MDT 2020
06:25:07 up 76 days, 10:53, 1 user, load average: 0.46, 0.27, 0.27
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
pi tty7 :0 24Feb20 76days 1:29m 2.81s /usr/bin/lxsession -s LXDE-pi -e LXDE