Thu May 28 06:25:11 MDT 2020 06:25:11 up 7:30, 1 user, load average: 0.75, 0.32, 0.29 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 22:25 8:08m 25.74s 0.24s /usr/bin/lxsession -s LXDE-pi -e LXDE 185.82.215.92 - - [28/May/2020:12:49:30 +0000] "GET / HTTP/1.1" 200 25000 "" "curl/7.64.0" 162.243.138.26 - - [28/May/2020:13:44:46 +0000] "GET /ReportServer HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 47.94.225.157 - - [28/May/2020:14:06:14 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 47.94.225.157 - - [28/May/2020:14:06:16 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 47.94.225.157 - - [28/May/2020:14:06:18 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 47.94.225.157 - - [28/May/2020:14:06:20 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 47.94.225.157 - - [28/May/2020:14:06:22 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 47.94.225.157 - - [28/May/2020:14:06:24 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 47.94.225.157 - - [28/May/2020:14:06:26 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 47.94.225.157 - - [28/May/2020:14:06:28 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 47.94.225.157 - - [28/May/2020:14:06:30 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 47.94.225.157 - - [28/May/2020:14:06:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 185.217.161.151 - - [28/May/2020:16:19:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.142.225 - - [28/May/2020:16:43:47 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 162.250.19.7 - - [28/May/2020:16:51:32 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:16:51:49 +0000] "GET /ac0xl/logs/2020.05.28 HTTP/1.1" 200 14080 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 159.203.77.59 - - [28/May/2020:16:55:45 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 207.180.226.26 - - [28/May/2020:17:40:05 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 46.49.84.33 - - [28/May/2020:17:47:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.250.19.7 - - [28/May/2020:17:56:48 +0000] "GET /videos/knight-2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 200 42912006 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 167.99.40.21 - - [28/May/2020:18:03:39 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 162.250.19.7 - - [28/May/2020:18:13:04 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [28/May/2020:18:13:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [28/May/2020:18:13:29 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [28/May/2020:18:14:40 +0000] "GET /videos/knight-2020-05-20AreUndergroundPrisonsBeingBuilt-Comments.txt HTTP/1.1" 200 1669 "http://162.250.19.7/videos/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [28/May/2020:18:15:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [28/May/2020:18:35:42 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:18:35:49 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-comments.txt HTTP/1.1" 200 1669 "http://162.250.19.7/videos/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:18:36:07 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 200 528190 "http://162.250.19.7/videos/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:18:43:14 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [28/May/2020:18:55:02 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 200 306743544 "http://162.250.19.7/videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:19:08:37 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:19:08:44 +0000] "GET /ac0xl/www/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:19:11:54 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:19:12:36 +0000] "GET /ac0xl/logs/2020.05.28 HTTP/1.1" 304 0 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:19:19:09 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [28/May/2020:19:19:14 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-comments.txt HTTP/1.1" 304 0 "http://162.250.19.7/videos/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 66.240.205.34 - - [28/May/2020:20:51:50 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 177.9.193.17 - - [28/May/2020:21:22:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 177.9.193.17 - - [28/May/2020:21:22:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 142.93.202.82 - - [28/May/2020:21:27:09 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 195.54.160.130 - - [28/May/2020:22:16:56 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 217.128.0.26 - - [28/May/2020:22:24:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 195.54.160.130 - - [28/May/2020:22:25:51 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.130 - - [28/May/2020:22:25:51 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.130 - - [28/May/2020:22:41:15 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 103.149.192.152 - - [28/May/2020:23:14:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 170.81.247.204 - - [28/May/2020:23:24:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 190.128.154.222 - - [28/May/2020:23:32:09 +0000] "HEAD / HTTP/1.1" 200 0 "" "" 190.128.154.222 - - [28/May/2020:23:32:10 +0000] "GET / HTTP/1.1" 200 25000 "" "" 190.128.154.222 - - [28/May/2020:23:32:10 +0000] "HEAD /invoker/EJBInvokerServlet HTTP/1.1" 404 0 "" "" 82.62.16.201 - - [29/May/2020:00:35:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 82.62.16.201 - - [29/May/2020:00:35:19 +0000] "GET / HTTP/1.0" 200 25000 "" "" 193.42.99.162 - - [29/May/2020:00:46:37 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.42.99.162 - - [29/May/2020:00:46:37 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 88.130.218.195 - - [29/May/2020:01:20:32 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 193.42.99.162 - - [29/May/2020:01:40:56 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.42.99.162 - - [29/May/2020:01:40:56 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 195.54.160.130 - - [29/May/2020:02:00:56 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 77.159.67.13 - - [29/May/2020:03:20:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 172.105.89.161 - - [29/May/2020:03:45:00 +0000] "GET /0bef HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.116 Safari/537.36" 78.187.193.70 - - [29/May/2020:04:04:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 168.195.254.245 - - [29/May/2020:04:27:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 109.194.10.133 - - [29/May/2020:05:48:23 +0000] "GET /shell?busybox HTTP/1.1" 400 0 "" "Mozilla/5.0" 109.194.10.133 - - [29/May/2020:05:48:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 167.172.124.181 - - [29/May/2020:06:58:32 +0000] "GET / HTTP/1.1" 200 25000 "" "" 192.162.237.35 - - [29/May/2020:07:24:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 178.119.154.209 - - [29/May/2020:07:59:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 185.140.101.75 - - [29/May/2020:09:40:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 24.55.206.83 - - [29/May/2020:09:42:17 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 24.55.206.83 - - [29/May/2020:09:42:17 +0000] "GET / HTTP/1.1" 200 25000 "" "" 41.50.101.212 - - [29/May/2020:10:44:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 165.22.68.95 - - [29/May/2020:11:20:38 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" Fri May 29 06:25:07 MDT 2020 06:25:07 up 1 day, 7:30, 1 user, load average: 0.38, 0.27, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Wed22 32:08m 2:47 0.65s /usr/bin/lxsession -s LXDE-pi -e LXDE