Tue Jun 9 06:25:07 MDT 2020 06:25:07 up 9 days, 11:33, 1 user, load average: 0.35, 0.24, 0.25 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 30May20 9days 7:14 0.90s /usr/bin/lxsession -s LXDE-pi -e LXDE 194.61.26.34 - - [09/Jun/2020:12:50:42 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 68.183.93.200 - - [09/Jun/2020:13:08:24 +0000] "GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1" 404 0 "" "ZmEu" 68.183.93.200 - - [09/Jun/2020:13:08:24 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 68.183.93.200 - - [09/Jun/2020:13:08:25 +0000] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 68.183.93.200 - - [09/Jun/2020:13:08:25 +0000] "GET /pma/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 68.183.93.200 - - [09/Jun/2020:13:08:26 +0000] "GET /myadmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 68.183.93.200 - - [09/Jun/2020:13:08:26 +0000] "GET /MyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 106.12.194.97 - - [09/Jun/2020:14:29:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 106.12.194.97 - - [09/Jun/2020:14:29:54 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.12.194.97 - - [09/Jun/2020:14:29:54 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.12.194.97 - - [09/Jun/2020:14:29:55 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.12.194.97 - - [09/Jun/2020:14:29:55 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.12.194.97 - - [09/Jun/2020:14:29:56 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.12.194.97 - - [09/Jun/2020:14:29:59 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.12.194.97 - - [09/Jun/2020:14:30:01 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.12.194.97 - - [09/Jun/2020:14:30:02 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 106.12.194.97 - - [09/Jun/2020:14:30:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 128.14.209.226 - - [09/Jun/2020:14:51:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 87.103.170.105 - - [09/Jun/2020:15:04:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.54.160.135 - - [09/Jun/2020:15:22:53 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.135 - - [09/Jun/2020:15:33:38 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.135 - - [09/Jun/2020:15:33:38 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 178.73.215.171 - - [09/Jun/2020:15:34:04 +0000] "GET / HTTP/1.0" 200 25000 "" "" 172.104.108.109 - - [09/Jun/2020:15:50:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 195.54.160.135 - - [09/Jun/2020:15:50:20 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 47.89.192.12 - - [09/Jun/2020:15:50:31 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 222.186.61.115 - - [09/Jun/2020:16:16:13 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 202.162.199.22 - - [09/Jun/2020:16:30:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 31.217.212.42 - - [09/Jun/2020:16:31:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 123.158.49.152 - - [09/Jun/2020:16:34:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 222.82.51.240 - - [09/Jun/2020:16:34:13 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0" 113.128.104.109 - - [09/Jun/2020:16:34:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 113.128.104.109 - - [09/Jun/2020:16:34:19 +0000] "GET /english/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 113.128.104.109 - - [09/Jun/2020:16:34:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 39.96.90.139 - - [09/Jun/2020:17:19:29 +0000] "GET / HTTP/1.0" 200 25000 "" "" 119.76.36.156 - - [09/Jun/2020:17:37:33 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 192.35.168.144 - - [09/Jun/2020:18:04:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 213.92.191.250 - - [09/Jun/2020:18:08:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 62.171.171.32 - - [09/Jun/2020:18:39:37 +0000] "HEAD / HTTP/1.0" 200 0 "" "" 194.61.26.34 - - [09/Jun/2020:18:56:52 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 220.134.199.90 - - [09/Jun/2020:19:24:03 +0000] "GET / HTTP/1.1" 400 0 "" "" 112.169.77.158 - - [09/Jun/2020:19:32:13 +0000] "GET / HTTP/1.1" 400 0 "" "" 35.224.226.217 - - [09/Jun/2020:19:38:12 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 195.54.160.135 - - [09/Jun/2020:19:39:58 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 62.171.171.24 - - [09/Jun/2020:20:12:34 +0000] "HEAD / HTTP/1.0" 200 0 "" "" 83.97.20.21 - - [09/Jun/2020:20:41:29 +0000] "GET / HTTP/1.0" 200 25000 "" "" 59.126.6.11 - - [09/Jun/2020:20:51:55 +0000] "GET / HTTP/1.1" 400 0 "" "" 213.61.215.54 - - [09/Jun/2020:21:12:05 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36" 185.202.1.169 - - [09/Jun/2020:22:01:25 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 111.229.116.167 - - [09/Jun/2020:22:40:37 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.229.116.167 - - [09/Jun/2020:22:40:37 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 111.229.116.167 - - [09/Jun/2020:22:40:37 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.229.116.167 - - [09/Jun/2020:22:40:38 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.229.116.167 - - [09/Jun/2020:22:40:38 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.229.116.167 - - [09/Jun/2020:22:40:39 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.229.116.167 - - [09/Jun/2020:22:40:39 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.229.116.167 - - [09/Jun/2020:22:40:40 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.229.116.167 - - [09/Jun/2020:22:40:41 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 111.229.116.167 - - [09/Jun/2020:22:40:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 74.209.14.193 - - [09/Jun/2020:23:42:26 +0000] "GET / HTTP/1.1" 400 0 "" "" 35.221.156.44 - - [10/Jun/2020:00:19:59 +0000] "GET /t HTTP/1.1" 404 0 "" "Go-http-client/1.1" 202.79.60.142 - - [10/Jun/2020:00:24:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 71.6.232.4 - - [10/Jun/2020:01:07:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36" 103.113.111.222 - - [10/Jun/2020:01:14:50 +0000] "GET / HTTP/1.1" 400 0 "" "" 37.49.224.24 - - [10/Jun/2020:02:18:25 +0000] "GET / HTTP/1.1" 200 25000 "" "" 191.255.127.34 - - [10/Jun/2020:02:18:31 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 183.81.78.218 - - [10/Jun/2020:02:18:53 +0000] "GET / HTTP/1.1" 400 0 "" "" 42.115.70.81 - - [10/Jun/2020:02:23:05 +0000] "GET / HTTP/1.1" 400 0 "" "" 118.100.241.2 - - [10/Jun/2020:02:23:30 +0000] "GET / HTTP/1.1" 400 0 "" "" 201.138.160.147 - - [10/Jun/2020:02:54:07 +0000] "GET / HTTP/1.1" 400 0 "" "" 62.171.171.32 - - [10/Jun/2020:03:31:56 +0000] "HEAD / HTTP/1.0" 200 0 "" "" 195.54.160.135 - - [10/Jun/2020:03:37:57 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.135 - - [10/Jun/2020:03:45:26 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.135 - - [10/Jun/2020:03:45:26 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.135 - - [10/Jun/2020:04:02:12 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 167.99.40.21 - - [10/Jun/2020:05:12:24 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 162.243.138.123 - - [10/Jun/2020:06:29:53 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 195.54.160.135 - - [10/Jun/2020:07:09:15 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 172.104.108.109 - - [10/Jun/2020:07:25:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 45.201.163.75 - - [10/Jun/2020:07:43:56 +0000] "GET / HTTP/1.1" 400 0 "" "" 109.104.240.33 - - [10/Jun/2020:07:48:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 109.245.210.162 - - [10/Jun/2020:07:49:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 96.71.48.177 - - [10/Jun/2020:08:08:27 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 96.71.48.177 - - [10/Jun/2020:08:08:28 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 151.0.52.249 - - [10/Jun/2020:08:10:23 +0000] "GET / HTTP/1.1" 400 0 "" "" 190.94.148.37 - - [10/Jun/2020:08:46:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 65.24.200.144 - - [10/Jun/2020:10:00:34 +0000] "GET / HTTP/1.1" 400 0 "" "" 167.71.203.123 - - [10/Jun/2020:10:42:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.128 Safari/537.36" 167.71.203.123 - - [10/Jun/2020:10:42:24 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.128 Safari/537.36" 162.243.144.4 - - [10/Jun/2020:10:57:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 35.205.86.202 - - [10/Jun/2020:11:04:50 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 35.245.103.231 - - [10/Jun/2020:12:00:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.223.197.140 - - [10/Jun/2020:12:11:37 +0000] "GET / HTTP/1.1" 200 25000 "" "" Wed Jun 10 06:25:07 MDT 2020 06:25:07 up 10 days, 11:33, 1 user, load average: 0.36, 0.26, 0.27 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 30May20 10days 7:50 0.90s /usr/bin/lxsession -s LXDE-pi -e LXDE