43.166.247.82 - - [27/Nov/2025:16:27:39 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 91.251.37.113 - - [27/Nov/2025:15:46:06 +0330] "GET /wp-content/uploads/2020/12/logo2.png HTTP/1.1" 200 4490 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Safari/605.1.15" 185.39.19.49 - - [27/Nov/2025:16:40:50 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:12:56 +0330] "GET /404.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:07 +0330] "GET /users.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:21 +0330] "GET /admin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:37 +0330] "GET /dropdown.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:40 +0330] "GET /wp-header.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:45 +0330] "GET /radio.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:14:00 +0330] "GET /cong.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:14:01 +0330] "GET /options.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:14:07 +0330] "GET /wp-content/index.php?x=ooo HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:16 +0330] "GET /classwithtostring.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:19 +0330] "GET /wp-head.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:30 +0330] "GET /about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:42 +0330] "GET /alfanew.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:13:57 +0330] "GET /simple.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:14:04 +0330] "GET /alfa-rex.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:14:09 +0330] "GET /wp-admin/options.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.65.236.113 - - [27/Nov/2025:17:14:15 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 157.55.39.223 - - [27/Nov/2025:17:27:52 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/116.0.1938.76 Safari/537.36" 157.55.39.223 - - [27/Nov/2025:17:44:20 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/116.0.1938.76 Safari/537.36" 95.108.213.182 - - [27/Nov/2025:18:04:56 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 95.108.213.113 - - [27/Nov/2025:18:10:56 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 95.108.213.155 - - [27/Nov/2025:18:06:56 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 87.250.224.7 - - [27/Nov/2025:18:08:56 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 87.250.224.54 - - [27/Nov/2025:18:12:56 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 157.55.39.223 - - [27/Nov/2025:18:13:24 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/116.0.1938.76 Safari/537.36" 40.77.167.0 - - [27/Nov/2025:18:13:38 +0330] "GET /note/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/116.0.1938.76 Safari/537.36" 213.180.203.133 - - [27/Nov/2025:18:14:57 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 5.255.231.32 - - [27/Nov/2025:18:15:00 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 152.42.218.151 - - [27/Nov/2025:18:16:35 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 213.180.203.68 - - [27/Nov/2025:18:17:00 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 213.180.203.19 - - [27/Nov/2025:18:21:05 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 113.219.218.197 - - [27/Nov/2025:18:50:35 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 212.30.36.67 - - [27/Nov/2025:19:23:08 +0330] "GET /adminer.php HTTP/1.1" 301 20 "-" "python-requests/2.32.3" 45.154.98.144 - - [27/Nov/2025:19:53:19 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 51.79.137.110 - - [27/Nov/2025:20:10:41 +0330] "GET /postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 51.79.137.110 - - [27/Nov/2025:20:10:49 +0330] "GET /wp-content/postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 51.79.137.110 - - [27/Nov/2025:20:10:57 +0330] "GET /wp-admin/postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 37.114.48.221 - - [27/Nov/2025:21:15:26 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 37.114.48.221 - - [27/Nov/2025:21:16:02 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 43.153.182.11 - - [27/Nov/2025:22:14:08 +0330] "GET http://optimyar.com/wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 85.112.201.196 - - [27/Nov/2025:22:17:03 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 85.112.201.196 - - [27/Nov/2025:22:17:03 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 85.112.201.196 - - [27/Nov/2025:22:17:03 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 202.154.18.80 - - [27/Nov/2025:23:27:49 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 152.42.177.194 - - [27/Nov/2025:23:30:06 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.5652.134 Safari/537.36" 152.42.177.194 - - [27/Nov/2025:23:30:13 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.5850.92 Safari/537.36" 152.42.177.194 - - [27/Nov/2025:23:30:24 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.5592.148 Safari/537.36" 43.157.95.239 - - [27/Nov/2025:23:46:32 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 195.254.165.184 - - [28/Nov/2025:00:38:44 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36" 43.163.104.54 - - [28/Nov/2025:00:59:47 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 180.102.134.69 - - [28/Nov/2025:01:05:16 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 194.38.22.4 - - [28/Nov/2025:01:39:22 +0330] "GET /assets/jquery-file-upload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 403 17366 "-" "ALittle Client" 105.156.209.217 - - [28/Nov/2025:03:05:57 +0330] "GET /x.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 105.156.209.217 - - [28/Nov/2025:03:06:08 +0330] "GET /wso.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 105.156.209.217 - - [28/Nov/2025:03:06:13 +0330] "GET /srx.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 105.156.209.217 - - [28/Nov/2025:03:06:19 +0330] "GET /1337.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 105.156.209.217 - - [28/Nov/2025:03:06:24 +0330] "GET /xx.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 105.156.209.217 - - [28/Nov/2025:03:06:39 +0330] "GET /leaf.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 174.138.20.230 - - [28/Nov/2025:03:17:26 +0330] "GET /sftp-config.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 165.22.66.238 - - [28/Nov/2025:03:23:17 +0330] "GET / HTTP/1.1" 403 17366 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 174.138.20.230 - - [28/Nov/2025:03:17:31 +0330] "GET /.vscode/sftp.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 165.22.66.238 - - [28/Nov/2025:03:23:17 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17366 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 165.22.66.238 - - [28/Nov/2025:03:23:17 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17366 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 165.22.66.238 - - [28/Nov/2025:03:23:17 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17366 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 165.22.66.238 - - [28/Nov/2025:03:23:17 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 31.214.174.196 - - [28/Nov/2025:03:23:21 +0330] "POST /wp-cron.php?doing_wp_cron=1764287601.3822550773620605468750 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 165.22.66.238 - - [28/Nov/2025:03:23:17 +0330] "POST /wp-plain.php HTTP/1.1" 404 101719 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 165.22.66.238 - - [28/Nov/2025:03:23:23 +0330] "GET /heudifrd.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 49.232.241.93 - - [28/Nov/2025:03:37:12 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 102.98.96.95 - - [28/Nov/2025:03:49:28 +0330] "GET /wp-head.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 91.245.236.202 - - [28/Nov/2025:04:21:59 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.6943.127 Safari/537.36" 149.88.110.48 - - [28/Nov/2025:04:28:01 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 104.234.19.102 - - [28/Nov/2025:04:39:19 +0330] "GET /wp-admin/txets.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 216.24.219.154 - - [28/Nov/2025:04:39:05 +0330] "GET /txets.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 216.24.219.137 - - [28/Nov/2025:04:39:12 +0330] "GET /wp-content/txets.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 209.188.21.58 - - [28/Nov/2025:05:08:06 +0330] "GET / HTTP/1.1" 301 20 "-" "BurstTitleFetcher/isolated/2.1" 212.34.153.180 - - [28/Nov/2025:07:31:07 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 43.166.7.113 - - [28/Nov/2025:08:43:54 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 209.38.144.218 - - [28/Nov/2025:09:41:32 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0" 51.161.8.73 - - [28/Nov/2025:09:56:31 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.4; en-US; rv:1.9.2.2) Gecko/20100316 Firefox/3.6.2" 77.90.185.240 - - [28/Nov/2025:10:22:14 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "https://www.facebook.com/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:118.0.2) Gecko/20100101 Firefox/118.0.2" 77.90.185.240 - - [28/Nov/2025:10:22:25 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.57 Safari/537.36" 43.166.136.24 - - [28/Nov/2025:10:30:12 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:45:31 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:45:32 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:45:32 +0330] "GET /.well-known/acme-challenge/xa.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:45:47 +0330] "GET /403.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.205.103.113 - - [28/Nov/2025:10:45:53 +0330] "GET /aa.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:46:06 +0330] "GET /about.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.205.103.113 - - [28/Nov/2025:10:46:13 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:46:27 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:46:34 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:46:40 +0330] "GET /alfa.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:46:47 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:46:54 +0330] "GET /as.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:47:01 +0330] "GET /asasx.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:47:28 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:47:41 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:47:42 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:47:49 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:45:38 +0330] "GET /.well-known/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:45:42 +0330] "GET /1.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:45:59 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.205.103.113 - - [28/Nov/2025:10:46:20 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:47:08 +0330] "GET /asd.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:47:15 +0330] "GET /assets/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:47:22 +0330] "GET /assets/images/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:47:35 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:48:11 +0330] "GET /ds.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:48:17 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:48:24 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:48:57 +0330] "GET /gelay.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:49:22 +0330] "GET /gfile.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:49:31 +0330] "GET /gg.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:49:38 +0330] "GET /goods.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:49:46 +0330] "GET /i.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 45.154.98.144 - - [28/Nov/2025:10:54:52 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:47:56 +0330] "GET /dex.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:48:03 +0330] "GET /doc.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:48:31 +0330] "GET /files/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.103.113 - - [28/Nov/2025:10:48:38 +0330] "GET /files/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.103.113 - - [28/Nov/2025:10:48:49 +0330] "GET /function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 169.150.203.242 - - [28/Nov/2025:10:58:37 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 75.119.143.158 - - [28/Nov/2025:11:04:05 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 47.101.213.253 - - [28/Nov/2025:12:50:52 +0330] "GET /zb_users/plugin/UEditor/themes/default/images/cancelbutton.gif HTTP/1.1" 301 20 "http://optimyar.com/zb_users/plugin/UEditor/themes/default/images/cancelbutton.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 47.101.213.253 - - [28/Nov/2025:12:50:59 +0330] "GET /zb_users/plugin/UEditor/themes/default/images/cursor_v.gif HTTP/1.1" 301 20 "http://optimyar.com/zb_users/plugin/UEditor/themes/default/images/cursor_v.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 47.101.213.253 - - [28/Nov/2025:12:51:06 +0330] "GET /zb_users/emotion/face/Music.gif HTTP/1.1" 301 20 "http://optimyar.com/zb_users/emotion/face/Music.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 5.62.237.231 - - [28/Nov/2025:13:00:09 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" 36.41.75.167 - - [28/Nov/2025:13:37:46 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 17.246.23.64 - - [28/Nov/2025:13:50:26 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)" 17.246.23.64 - - [28/Nov/2025:13:50:30 +0330] "GET /courses/gams_compressed HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)" 66.249.66.13 - - [28/Nov/2025:14:17:52 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 119.249.100.107 - - [28/Nov/2025:14:25:14 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 110.249.202.11 - - [28/Nov/2025:14:31:05 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; https://zhanzhang.toutiao.com/)" 119.249.100.113 - - [28/Nov/2025:14:25:14 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 52.167.144.227 - - [28/Nov/2025:14:34:39 +0330] "GET /courses/mssp-mlro-14010510/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/116.0.1938.76 Safari/537.36" 23.81.34.216 - - [28/Nov/2025:15:22:22 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36" 196.251.100.176 - - [28/Nov/2025:15:33:16 +0330] "GET /assets/jquery-file-upload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 403 17366 "-" "ALittle Client" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/hotips/hotips.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; LYA-AL00) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.88 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-includes/js/jquery/ui/core.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; U; Android 1.6; en-us; HTC_TATTOO_A3288 Build/DRC79) AppleWebKit/528.5 (KHTML, like Gecko) Version/3.1.2 Mobile Safari/525.20.1" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //cdnjs.cloudflare.com/ajax/libs/gsap/2.1.3/TweenMax.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/533.17.8 (KHTML, like Gecko) Version/5.0.1 Safari/533.17.8" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/elements-handlers.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; U; Android 1.5; en-gb; T-Mobile_G2_Touch Build/CUPCAKE) AppleWebKit/528.5 (KHTML, like Gecko) Version/3.1.2 Mobile Safari/525.20.1" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js HTTP/1.1" 200 0 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0)" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/jet-blocks.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Maemo; Linux armv7l; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Fennec/2.0.1" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4853.129 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-includes/js/dist/i18n.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:20.0) Gecko/20100101 Firefox/20.0" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/jet-elements.min.js HTTP/1.1" 200 0 "-" "SearchExpress" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/elementor.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:5.0) Gecko/20100101 Firefox/5.0 Iceweasel/5.0" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/essential-addons-for-elementor-lite/assets/front-end/js/view/general.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 7.1.1; CPH1729) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.61 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery-migrate.min.js HTTP/1.1" 200 0 "-" "Java/1.6.0_13" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/lib/jsticky/jquery.jsticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.101 Safari/537.36 OPR/40.0.2308.62" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.71 (KHTML like Gecko) WebVideo/1.0.1.10 Version/7.0 Safari/537.71" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET /default.js HTTP/1.1" 200 0 "-" "Wget/1.9 cvs-stable (Red Hat modified)" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.min.js HTTP/1.1" 200 0 "-" "Opera/9.30 (Nintendo Wii; U; ; 2047-7; en)" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET /wp-emoji-release.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; MALNJS; rv:11.0) like Gecko" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/parallax-gallery/parallax-gallery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; CrOS x86_64 13982.88.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.162 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 11; RMX1931) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:51 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_3; en-us; Silk/1.0.13.81_10003810) AppleWebKit/533.16 (KHTML, like Gecko) Version/5.0 Safari/533.16 Silk-Accelerated=true" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/jet-tabs/assets/js/jet-tabs-frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 7.0; Moto G (5) Plus Build/NPNS25.137-35-5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/534.15 (KHTML, like Gecko) Ubuntu/10.10 Chromium/10.0.613.0 Chrome/10.0.613.0 Safari/534.15" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/lib/slick/slick.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; U; Linux i686; it; rv:1.9.2.3) Gecko/20100406 Firefox/3.6.3 (Swiftfox)" 149.50.97.212 - - [28/Nov/2025:15:40:53 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/animate-circle.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (iPad; CPU OS 10_0 like Mac OS X) AppleWebKit/601.1 (KHTML, like Gecko) CriOS/49.0.2623.109 Mobile/14A5335b Safari/601.1.46" 149.50.97.212 - - [28/Nov/2025:15:40:54 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36 HBPC/12.0.0.300" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 11; vivo 1906) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.79 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/essential-addons-for-elementor-lite/assets/front-end/js/view/general.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; FreeBSD amd64) AppleWebKit/535.22+ (KHTML, like Gecko) Chromium/17.0.963.56 Chrome/17.0.963.56 Safari/535.22+ Epiphany/2.30.6" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; OpenBSD amd64; rv:30.0) Gecko/20100101 Firefox/30.0" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/jet-blocks.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/elementor.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 8.0.0; Pixel 2 XL Build/OPD1.170816.004) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/jet-elements.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; MALNJS; rv:11.0) like Gecko" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/jet-tabs/assets/js/jet-tabs-frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-includes/js/jquery/ui/core.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; webOS/2.2.4; U; en-US) AppleWebKit/534.6 (KHTML, like Gecko) webOSBrowser/221.56 Safari/534.6 Pre/3.0" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 9; Redmi Note 8T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.61 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-includes/js/dist/i18n.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64; rv:39.0) Gecko/20100101 Firefox/39.0" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/lib/jsticky/jquery.jsticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 12; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.98 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-includes/js/dist/hooks.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (compatible; Konqueror/4.4; Linux 2.6.32-22-generic; X11; en_US) KHTML/4.4.3 (like Gecko) Kubuntu" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) GSA/209.1.445234187 Mobile/15E148 Safari/604.1" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/animate-circle.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.0.0 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 11; M2003J15SC) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1" 149.50.97.212 - - [28/Nov/2025:15:41:11 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-includes/js/dist/hooks.min.js HTTP/1.1" 200 0 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Maxthon 2.0)" 149.50.97.212 - - [28/Nov/2025:15:40:52 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/33.0.1750.152 Chrome/33.0.1750.152 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Opera/9.25 (Windows NT 6.0; U; en)" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/parallax-gallery/parallax-gallery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; U; Linux i686; rv:19.0) Gecko/20100101 Slackware/13 Firefox/19.0" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //cdnjs.cloudflare.com/ajax/libs/gsap/2.1.3/TweenMax.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/elements-handlers.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.56 (KHTML, like Gecko) Version/9.0 Safari/601.1.56" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:12.0) Gecko/20100101 Firefox/12.0" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/17.17134" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js HTTP/1.1" 200 0 "-" "iTunes/4.2 (Macintosh; U; PPC Mac OS X 10.2)" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/lib/slick/slick.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.84 Safari/537.36 OPR/85.0.4341.75" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET /default.js HTTP/1.1" 200 0 "-" "portalmmm/2.0 N410i(c20;TB)" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET /wp-emoji-release.min.js HTTP/1.1" 200 0 "-" "Mozilla/4.0 (compatible; Dillo 3.0)" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 12; SM-G991B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.61 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:10 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery-migrate.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (OS/2; Warp 4.5; rv:31.0) Gecko/20100101 Firefox/31.0 SeaMonkey/2.28" 149.50.97.212 - - [28/Nov/2025:15:41:30 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/jet-blocks.min.js HTTP/1.1" 503 807 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.36 Safari/535.7" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0 Safari/605.1.15" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/elements-handlers.min.js HTTP/1.1" 200 0 "-" "Opera/9.80 (Android; Opera Mini/9.0.1829/66.318; U; en) Presto/2.12.423 Version/12.16" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/hotips/hotips.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (PLAYSTATION 3; 1.10)" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 7.1.1; CPH1729) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.61 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/animate-circle.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Mobile/15E148 Safari/604.1" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.56 (KHTML, like Gecko) Version/9.0 Safari/601.1.56" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/jet-elements.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_1_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.41 YaBrowser/21.2.0.2458 Yowser/2.5 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; U; Linux i686; rv:19.0) Gecko/20100101 Slackware/13 Firefox/19.0" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/lib/jsticky/jquery.jsticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.101 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.0.0 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/elementor.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:8.0) Gecko/20100101 Firefox/8.0" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-includes/js/dist/hooks.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; arm; Android 10; HRY-LX1T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 YaBrowser/22.3.1.87.00 SA/3 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.82 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/lib/slick/slick.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 11; SM-A526U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/jet-tabs/assets/js/jet-tabs-frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/28.0.1469.0 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:30 +0330] "GET //optimyar.com/wp-content/plugins/essential-addons-for-elementor-lite/assets/front-end/js/view/general.min.js HTTP/1.1" 200 0 "-" "Vodafone/1.0/V802SE/SEJ001 Browser/SEMC-Browser/4.1" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 4.4.2; SAMSUNG-SM-T537A Build/KOT49H) AppleWebKit/537.36 (KHTML like Gecko) Chrome/35.0.1916.141 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:14 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/hotips/hotips.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 11; SM-A505F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.61 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/parallax-gallery/parallax-gallery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; POCOPHONE F1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //cdnjs.cloudflare.com/ajax/libs/gsap/2.1.3/TweenMax.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (compatible; Konqueror/4.1; DragonFly) KHTML/4.1.4 (like Gecko)" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20120403211507 Firefox/12.0" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.109 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4889.0 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0 Safari/605.1.15" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery-migrate.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:63.0) Gecko/20100101 Firefox/63.0" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.60 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-includes/js/dist/i18n.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; U; Linux i686; en-us) AppleWebKit/528.5 (KHTML, like Gecko, Safari/528.5 ) lt-GtkLauncher" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET /default.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 11; GM1910) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:29 +0330] "GET /wp-emoji-release.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.11) Gecko/2009060309 Ubuntu/9.10 (karmic) Firefox/3.0.11" 149.50.97.212 - - [28/Nov/2025:15:41:30 +0330] "GET //optimyar.com/wp-includes/js/jquery/ui/core.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/hotips/hotips.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_2; rv:10.0.1) Gecko/20100101 Firefox/10.0.1" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (iPad; CPU OS 10_0 like Mac OS X) AppleWebKit/601.1 (KHTML, like Gecko) CriOS/49.0.2623.109 Mobile/14A5335b Safari/601.1.46" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //cdnjs.cloudflare.com/ajax/libs/gsap/2.1.3/TweenMax.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/527 (KHTML, like Gecko, Safari/419.3) Arora/0.6 (Change: )" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; NetBSD) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.116 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/537.13+ (KHTML, like Gecko) Version/5.1.7 Safari/534.57.2" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js HTTP/1.1" 200 0 "-" "BlackBerry8320/4.2.2 Profile/MIDP-2.0 Configuration/CLDC-1.1 VendorID/100" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/parallax-gallery/parallax-gallery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:16.0) Gecko/16.0 Firefox/16.0" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/lib/jsticky/jquery.jsticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/jet-elements.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US) AppleWebKit/528.16 (KHTML, like Gecko, Safari/528.16) OmniWeb/v622.8.0.112941" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/essential-addons-for-elementor-lite/assets/front-end/js/view/general.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (iPad; CPU OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML like Gecko) Mobile/12A405 Version/7.0 Safari/9537.53" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.89 Vivaldi/1.0.94.2 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/jet-tabs/assets/js/jet-tabs-frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.74 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/animate-circle.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1) Gecko/20061024 Firefox/2.0 (Swiftfox)" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-includes/js/dist/hooks.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/534.24 (KHTML, like Gecko) Ubuntu/10.10 Chromium/12.0.703.0 Chrome/12.0.703.0 Safari/534.24" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-includes/js/jquery/ui/core.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; U; Android 4.1.2; en-us; LG-P870/P87020d Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.60 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/elements-handlers.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_0 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/14A346 Safari/602.1" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; MAR-LX1B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/jet-blocks.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-includes/js/dist/i18n.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 11; RMX2161) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.85 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/lib/slick/slick.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; CrOS aarch64 14526.89.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.133 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/elementor.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 5.1; Lenovo TAB 2 A8-50LC) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.85 Safari/537.36 OPR/66.2.3445.62346" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery-migrate.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_4; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.464.0 Safari/534.3" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET /wp-emoji-release.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; U; Android 2.2; en-us; Nexus One Build/FRF91) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.141 YaBrowser/22.3.3.865 Yowser/2.5 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; VOG-L29) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.79 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/smartmenus/jquery.smartmenus.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux x86_64; en-US; rv:2.0b2pre) Gecko/20100712 Minefield/4.0b2pre" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-includes/js/dist/i18n.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 8.0.0; SAMSUNG SM-G935F) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/12.1 Chrome/79.0.3945.136 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/hotips/hotips.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/jet-tabs/assets/js/jet-tabs-frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; Redmi Note 9 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 11; Redmi Note 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.61 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-includes/js/dist/hooks.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:25.0) Gecko/20100101 Firefox/25.0" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Maxthon/4.4.6.1000 Chrome/30.0.1599.101 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:08 +0330] "GET //cdnjs.cloudflare.com/ajax/libs/gsap/2.1.3/TweenMax.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 4.4.2; LGMS323 Build/KOT49I.MS32310b) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.103 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:08 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/webpack.runtime.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; moto g(7) plus) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:08 +0330] "GET /wp-emoji-release.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 12; SM-G973F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:08 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/lib/slick/slick.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; CrOS aarch64 14388.61.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.107 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:09 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/600.8.9 (KHTML, like Gecko) Maxthon/4.5.2" 149.50.97.212 - - [28/Nov/2025:15:41:48 +0330] "GET /default.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/532.4 (KHTML, like Gecko) Chrome/4.0.237.0 Safari/532.4 Debian" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/js/elements-handlers.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/jet-elements/assets/js/jet-elements.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Safari/605.1.15" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.2; rv:20.0) Gecko/20121202 Firefox/20.0" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor/assets/js/frontend.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5030.0 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementor-extras/assets/lib/parallax-gallery/parallax-gallery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/96.0.4664.101 Mobile/15E148 Safari/604.1" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-includes/js/jquery/ui/core.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 Edg/84.0.522.52" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/animate-circle.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 9; Z6201V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery-migrate.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.76 Safari/537.36 OPR/19.0.1326.56" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/elementor.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.5 Mobile/15E148 Safari/604.1" 149.50.97.212 - - [28/Nov/2025:15:42:07 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/jet-blocks.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; U; Android 10; zh-Hans-CN; SPN-AL00 Build/HUAWEISPN-AL00) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.108 Quark/5.4.9.201 Mobile Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:08 +0330] "GET //optimyar.com/wp-content/plugins/jet-blocks/assets/js/lib/jsticky/jquery.jsticky.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:08 +0330] "GET //optimyar.com/wp-includes/js/jquery/jquery.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" 149.50.97.212 - - [28/Nov/2025:15:42:08 +0330] "GET //optimyar.com/wp-content/plugins/essential-addons-for-elementor-lite/assets/front-end/js/view/general.min.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (compatible; Konqueror/3.3; Linux 2.6.8-gentoo-r3; X11;" 149.50.97.212 - - [28/Nov/2025:15:42:09 +0330] "GET /default.js HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; U; Android 2.2; en-us; ADR6300 Build/FRF91) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1" 187.108.73.131 - - [28/Nov/2025:17:10:35 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 54.174.116.42 - - [28/Nov/2025:15:51:30 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Maemo; Linux armv7l; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Fennec/2.0.1" 170.106.107.87 - - [28/Nov/2025:16:57:59 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 37.46.196.22 - - [28/Nov/2025:17:16:28 +0330] "GET /index.php?%ADd+cgi.force_redirect%3D0+%ADd+cgi.redirect_status_env%3D0+%ADd+fastcgi.impersonate%3D1+%ADd+open_basedir%3D+%ADd+disable_functions%3D+%ADd+auto_prepend_file%3Dphp://input+%ADd+allow_url_include%3D1+%ADd+allow_url_fopen%3D1 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 37.46.196.22 - - [28/Nov/2025:17:16:47 +0330] "GET /php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+cgi.redirect_status_env%3D0+%ADd+fastcgi.impersonate%3D1+%ADd+open_basedir%3D+%ADd+disable_functions%3D+%ADd+auto_prepend_file%3Dphp://input+%ADd+allow_url_include%3D1+%ADd+allow_url_fopen%3D1 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 37.46.196.22 - - [28/Nov/2025:17:17:00 +0330] "GET /php/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+cgi.redirect_status_env%3D0+%ADd+fastcgi.impersonate%3D1+%ADd+open_basedir%3D+%ADd+disable_functions%3D+%ADd+auto_prepend_file%3Dphp://input+%ADd+allow_url_include%3D1+%ADd+allow_url_fopen%3D1 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 37.46.196.22 - - [28/Nov/2025:17:17:26 +0330] "GET /php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+cgi.redirect_status_env%3D0+%ADd+fastcgi.impersonate%3D1+%ADd+open_basedir%3D+%ADd+disable_functions%3D+%ADd+auto_prepend_file%3Dphp://input+%ADd+allow_url_include%3D1+%ADd+allow_url_fopen%3D1 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 43.130.15.147 - - [28/Nov/2025:17:55:53 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 35.87.166.195 - - [28/Nov/2025:17:14:51 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/68.0.3440.106 Safari/537.36" 35.87.166.195 - - [28/Nov/2025:17:14:57 +0330] "GET /wp-content/uploads/2020/12/logo2.png HTTP/1.1" 200 4490 "https://optimyar.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/68.0.3440.106 Safari/537.36" 37.46.196.22 - - [28/Nov/2025:17:17:11 +0330] "GET /cgi-bin/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+cgi.redirect_status_env%3D0+%ADd+fastcgi.impersonate%3D1+%ADd+open_basedir%3D+%ADd+disable_functions%3D+%ADd+auto_prepend_file%3Dphp://input+%ADd+allow_url_include%3D1+%ADd+allow_url_fopen%3D1 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 37.46.196.22 - - [28/Nov/2025:17:17:40 +0330] "GET /php.exe?%ADd+cgi.force_redirect%3D0+%ADd+cgi.redirect_status_env%3D0+%ADd+fastcgi.impersonate%3D1+%ADd+open_basedir%3D+%ADd+disable_functions%3D+%ADd+auto_prepend_file%3Dphp://input+%ADd+allow_url_include%3D1+%ADd+allow_url_fopen%3D1 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 37.46.196.22 - - [28/Nov/2025:17:17:53 +0330] "GET /php/php.exe?%ADd+cgi.force_redirect%3D0+%ADd+cgi.redirect_status_env%3D0+%ADd+fastcgi.impersonate%3D1+%ADd+open_basedir%3D+%ADd+disable_functions%3D+%ADd+auto_prepend_file%3Dphp://input+%ADd+allow_url_include%3D1+%ADd+allow_url_fopen%3D1 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 8.134.215.114 - - [28/Nov/2025:17:38:37 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36 Edg/129.0.0.0" 196.127.140.150 - - [28/Nov/2025:18:20:48 +0330] "GET /.env HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 66.249.66.13 - - [28/Nov/2025:19:02:47 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 142.93.45.10 - - [28/Nov/2025:18:54:20 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 138.68.4.127 - - [28/Nov/2025:19:15:10 +0330] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 5.77.192.239 - - [28/Nov/2025:19:34:45 +0330] "GET /wp-login.php HTTP/1.1" 301 0 "-" "Opera/9.80 (Windows NT 5.1; U; ru) Presto/2.9.168 Version/11.50" 104.131.189.187 - - [28/Nov/2025:19:23:34 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 51.222.24.119 - - [28/Nov/2025:19:34:49 +0330] "GET /wp-content/uploads/2020/12/logo2.png HTTP/1.1" 200 4490 "https://optimyar.com/" "Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecko/20100101 Firefox/57.0" 185.213.139.162 - - [28/Nov/2025:19:50:42 +0330] "GET / HTTP/1.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" 185.213.139.162 - - [28/Nov/2025:19:50:44 +0330] "GET / HTTP/1.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" 205.169.39.70 - - [28/Nov/2025:21:13:03 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 205.169.39.70 - - [28/Nov/2025:21:12:39 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 205.169.39.57 - - [28/Nov/2025:21:13:02 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36" 212.77.181.70 - - [28/Nov/2025:21:42:01 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0" 212.77.181.70 - - [28/Nov/2025:21:42:01 +0330] "GET /sevices/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Edg/142.0.0.0" 91.224.92.112 - - [28/Nov/2025:22:36:11 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 91.224.92.112 - - [28/Nov/2025:22:36:22 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 91.224.92.112 - - [28/Nov/2025:22:36:34 +0330] "GET /login HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 91.224.92.112 - - [28/Nov/2025:22:36:40 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 91.224.92.112 - - [28/Nov/2025:22:36:45 +0330] "GET /wp-login HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0" 91.224.92.112 - - [28/Nov/2025:22:36:55 +0330] "GET /wordpress/wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0" 91.224.92.112 - - [28/Nov/2025:22:37:00 +0330] "GET /blog/wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 91.224.92.112 - - [28/Nov/2025:22:37:06 +0330] "GET /wp/wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0" 91.224.92.112 - - [28/Nov/2025:22:37:11 +0330] "GET /cms/wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 43.159.138.217 - - [28/Nov/2025:23:24:00 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 185.27.132.26 - - [28/Nov/2025:23:47:06 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 185.27.132.26 - - [28/Nov/2025:23:47:06 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 185.27.132.26 - - [28/Nov/2025:23:47:06 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 43.130.154.56 - - [29/Nov/2025:00:31:10 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 199.45.154.135 - - [29/Nov/2025:01:02:42 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 185.2.4.79 - - [29/Nov/2025:01:14:27 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 185.2.4.79 - - [29/Nov/2025:01:14:27 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 185.2.4.79 - - [29/Nov/2025:01:14:27 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 182.42.111.213 - - [29/Nov/2025:02:29:04 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 45.80.158.175 - - [29/Nov/2025:04:20:12 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.175 - - [29/Nov/2025:04:20:13 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.175 - - [29/Nov/2025:04:20:12 +0330] "POST /wp-plain.php HTTP/1.1" 404 101649 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.175 - - [29/Nov/2025:04:20:12 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.175 - - [29/Nov/2025:04:20:12 +0330] "GET / HTTP/1.1" 403 17364 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.175 - - [29/Nov/2025:04:20:12 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 31.214.174.196 - - [29/Nov/2025:04:20:16 +0330] "POST /wp-cron.php?doing_wp_cron=1764377416.8020169734954833984375 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 45.80.158.175 - - [29/Nov/2025:04:20:19 +0330] "GET /ruixeogh.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.204 - - [29/Nov/2025:04:49:09 +0330] "GET /wp-header.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.204 - - [29/Nov/2025:04:48:39 +0330] "GET /404.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.204 - - [29/Nov/2025:04:48:43 +0330] "GET /users.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.204 - - [29/Nov/2025:04:48:46 +0330] "GET /classwithtostring.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.204 - - [29/Nov/2025:04:48:47 +0330] "GET /wp-head.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.204 - - [29/Nov/2025:04:48:52 +0330] "GET /admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.204 - - [29/Nov/2025:04:48:54 +0330] "GET /about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.204 - - [29/Nov/2025:04:48:57 +0330] "GET /dropdown.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 178.80.74.127 - - [29/Nov/2025:05:04:28 +0330] "GET /wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 66.249.66.1 - - [29/Nov/2025:04:53:33 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 103.87.212.133 - - [29/Nov/2025:05:04:36 +0330] "GET /wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 201.113.114.181 - - [29/Nov/2025:05:04:43 +0330] "GET /wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 157.245.5.3 - - [29/Nov/2025:05:19:27 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 103.52.212.8 - - [29/Nov/2025:05:49:01 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 43.173.1.69 - - [29/Nov/2025:06:13:54 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 220.247.224.162 - - [29/Nov/2025:07:02:15 +0330] "GET /wp-content/plugins/pwnd/pwnd.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" 220.247.224.162 - - [29/Nov/2025:07:02:20 +0330] "GET /wp-content/plugins/pwnd-1/pwnd.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" 220.247.224.162 - - [29/Nov/2025:07:02:25 +0330] "GET /wp-content/plugins/pwnd-2/pwnd.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" 220.247.224.162 - - [29/Nov/2025:07:02:30 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" 170.106.35.153 - - [29/Nov/2025:07:08:40 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 45.154.98.45 - - [29/Nov/2025:07:47:40 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.154.98.144 - - [29/Nov/2025:07:49:58 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 208.84.101.66 - - [29/Nov/2025:08:25:40 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.43.70.143 - - [29/Nov/2025:08:45:50 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 13.218.169.125 - - [29/Nov/2025:08:51:04 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 2.58.56.167 - - [29/Nov/2025:09:16:44 +0330] "GET /wp-admin/setup-config.php HTTP/1.1" 409 2838 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 2.189.80.64 - - [29/Nov/2025:09:19:07 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_6_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.6.2 Mobile/22G100 Safari/604.1" 173.44.155.83 - - [29/Nov/2025:09:33:55 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 173.44.155.83 - - [29/Nov/2025:09:34:35 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 64.23.139.223 - - [29/Nov/2025:09:33:21 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 173.44.155.83 - - [29/Nov/2025:09:35:02 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 5.121.20.180 - - [29/Nov/2025:10:24:41 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:145.0) Gecko/20100101 Firefox/145.0" 124.158.160.61 - - [29/Nov/2025:10:14:12 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 82.118.29.47 - - [29/Nov/2025:10:51:52 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36" 163.172.106.185 - - [29/Nov/2025:10:52:21 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 163.172.106.185 - - [29/Nov/2025:10:52:21 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 163.172.106.185 - - [29/Nov/2025:10:52:21 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 82.118.29.5 - - [29/Nov/2025:11:39:56 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36" 87.121.84.125 - - [29/Nov/2025:11:47:12 +0330] "GET /assets/jquery-file-upload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 403 17364 "-" "ALittle Client" 193.202.12.75 - - [29/Nov/2025:11:50:49 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 213.109.163.76 - - [29/Nov/2025:12:22:44 +0330] "GET /wp-content/uploads/2020/12/logo2.png HTTP/1.1" 200 4490 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_8_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.7 Mobile/15E148 Safari/604.1" 43.166.255.122 - - [29/Nov/2025:12:24:32 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 204.18.207.152 - - [29/Nov/2025:13:29:45 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/140.0.7339.122 Mobile/15E148 Safari/604.1" 43.135.135.57 - - [29/Nov/2025:13:18:26 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 45.130.104.242 - - [29/Nov/2025:13:31:00 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 89.187.187.69 - - [29/Nov/2025:14:53:21 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 223.15.245.170 - - [29/Nov/2025:15:23:32 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 157.245.5.3 - - [29/Nov/2025:16:06:44 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 5.219.37.1 - - [29/Nov/2025:16:04:14 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" 20.238.26.47 - - [29/Nov/2025:16:32:18 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Safari/537.36" 103.153.183.1 - - [29/Nov/2025:16:34:57 +0330] "GET /uploaded_script.php HTTP/1.1" 403 6889 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 220.181.51.92 - - [29/Nov/2025:16:36:46 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 220.181.51.116 - - [29/Nov/2025:16:37:01 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 45.154.98.45 - - [29/Nov/2025:17:44:31 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 124.156.179.141 - - [29/Nov/2025:18:07:17 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 98.88.85.238 - - [29/Nov/2025:18:18:45 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 43.130.32.245 - - [29/Nov/2025:19:07:30 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 64.227.150.179 - - [29/Nov/2025:19:11:19 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 77.90.185.245 - - [29/Nov/2025:18:58:01 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 45.130.104.242 - - [29/Nov/2025:19:11:59 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 146.70.24.43 - - [29/Nov/2025:19:38:13 +0330] "GET /courses/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" 130.195.240.17 - - [29/Nov/2025:20:04:11 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 194.38.22.4 - - [29/Nov/2025:20:16:22 +0330] "GET /assets/jquery-file-upload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 403 17366 "-" "ALittle Client" 136.243.228.198 - - [29/Nov/2025:20:52:05 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; DataForSeoBot/1.0; +https://dataforseo.com/dataforseo-bot)" 157.173.101.17 - - [29/Nov/2025:21:42:29 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 144.124.248.157 - - [29/Nov/2025:21:44:33 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.1" 144.124.248.157 - - [29/Nov/2025:21:44:37 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.1" 144.124.248.157 - - [29/Nov/2025:21:44:41 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.1" 157.245.5.3 - - [29/Nov/2025:22:03:52 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 106.227.49.113 - - [29/Nov/2025:22:10:11 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 124.158.160.61 - - [29/Nov/2025:22:14:12 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 193.143.1.119 - - [29/Nov/2025:22:27:52 +0330] "GET /simple.php?p=2f686f6d652f7074317464616379696b39722f7075626c69635f68746d6c&tod=75706c6f6164 HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:53 +0330] "GET /qindex.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:54 +0330] "GET /wp-atom.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:55 +0330] "GET /unlockindex.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:59 +0330] "GET /atomlib.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:28:00 +0330] "GET /nf_tracking.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:28:02 +0330] "GET /alfanew.php7 HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:28:03 +0330] "GET /wp-info.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:28:04 +0330] "GET /inputs.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:28:05 +0330] "GET /cong.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:28:09 +0330] "GET /x.php?action=768776e296b6f286f26796e2a72607e2972647 HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:47 +0330] "GET /wp-ver.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:48 +0330] "GET /inc.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:49 +0330] "GET /inputs.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:51 +0330] "GET /atomlib.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:56 +0330] "GET /lockindex.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:27:58 +0330] "GET /csv.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:28:06 +0330] "GET /style.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 193.143.1.119 - - [29/Nov/2025:22:28:08 +0330] "GET /wp-commentin.php?pass=f0aab4595a024d626315fb786dce8282 HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 195.24.236.45 - - [29/Nov/2025:23:31:31 +0330] "GET /postnews.php HTTP/1.1" 301 20 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [29/Nov/2025:23:46:54 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17366 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 157.245.5.3 - - [29/Nov/2025:23:58:10 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 4.241.208.113 - - [29/Nov/2025:23:46:54 +0330] "GET / HTTP/1.1" 403 17366 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [29/Nov/2025:23:46:54 +0330] "POST /wp-plain.php HTTP/1.1" 404 102464 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:00:00:12 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17366 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:00:00:12 +0330] "POST /wp-plain.php HTTP/1.1" 404 102464 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 43.166.134.47 - - [30/Nov/2025:00:09:46 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 4.241.208.113 - - [30/Nov/2025:00:00:12 +0330] "GET / HTTP/1.1" 403 17366 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 157.245.5.3 - - [30/Nov/2025:00:28:42 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:49:27 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:49:27 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:49:27 +0330] "GET /.well-known/acme-challenge/xa.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:50:07 +0330] "GET /1.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:50:12 +0330] "GET /403.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:50:17 +0330] "GET /aa.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:50:23 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:50:48 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:51:22 +0330] "GET /asasx.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:51:30 +0330] "GET /asd.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:51:37 +0330] "GET /assets/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:51:51 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:52:10 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:52:10 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:52:17 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:52:24 +0330] "GET /dex.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:52:50 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:50:00 +0330] "GET /.well-known/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:50:29 +0330] "GET /about.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:50:35 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:50:41 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.205.225.47 - - [30/Nov/2025:00:50:56 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:51:02 +0330] "GET /alfa.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:51:09 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:51:15 +0330] "GET /as.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:51:44 +0330] "GET /assets/images/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:51:58 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:52:31 +0330] "GET /doc.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:52:37 +0330] "GET /ds.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:52:44 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:52:57 +0330] "GET /files/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:53:04 +0330] "GET /files/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:53:14 +0330] "GET /function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:53:28 +0330] "GET /gfile.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:53:35 +0330] "GET /gg.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:53:55 +0330] "GET /images/images/about.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:54:28 +0330] "GET /index/function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:54:49 +0330] "GET /inputs.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:54:56 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:55:10 +0330] "GET /manager.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:55:17 +0330] "GET /modules/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:55:31 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:55:38 +0330] "GET /past.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:55:59 +0330] "GET /robots.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:56:13 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:56:40 +0330] "GET /wp-admin.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:56:47 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:57:00 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:57:12 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:57:12 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:57:12 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:53:21 +0330] "GET /gelay.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:53:42 +0330] "GET /goods.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:53:48 +0330] "GET /i.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:54:02 +0330] "GET /images/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:54:14 +0330] "GET /inc.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:54:21 +0330] "GET /index.bak.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:54:35 +0330] "GET /info.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:54:42 +0330] "GET /ini.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:55:03 +0330] "GET /item.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:55:24 +0330] "GET /moon.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:55:45 +0330] "GET /php/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:55:52 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:56:06 +0330] "GET /shop.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:56:19 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:56:26 +0330] "GET /upload/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:56:33 +0330] "GET /vendor/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:57:48 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:57:13 +0330] "GET /wp-admin/css/colors/light/function.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:57:24 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:57:24 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:57:24 +0330] "GET /wp-admin/includes/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:57:24 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:57:36 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:58:13 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:58:54 +0330] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:59:06 +0330] "GET /wp-blog-header.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:59:12 +0330] "GET /wp-comments.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:59:25 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:59:26 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:59:41 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:59:56 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:59:57 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:59:57 +0330] "GET /wp-content/plugins/HelloDollyV2/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:58:00 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:58:01 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:58:01 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:58:29 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:58:29 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:58:41 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:59:18 +0330] "GET /wp-conflg.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:00:59:33 +0330] "GET /wp-content/Geforce.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:00:59:48 +0330] "GET /wp-content/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:00:38 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:00:50 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:00:50 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:01:06 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:01:07 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:01:34 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:01:34 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:00:05 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:00:14 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:00:59 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 500 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:00:59 +0330] "GET /wp-content/themes/themes.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:01:12 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:01:13 +0330] "GET /wp-content/uploads/Geforce.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:01:19 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:01:25 +0330] "GET /wp-good.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:01:53 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:01:53 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:01:53 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:02:07 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:02:08 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:02:16 +0330] "GET /wp-includes/SimplePie/autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:02:35 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:02:50 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:01:34 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:01:43 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:01:43 +0330] "GET /wp-includes/IXR/test1.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:02:01 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:02:25 +0330] "GET /wp-includes/SimplePie/chosen.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:02:59 +0330] "GET /wp-includes/Text/wp-conflg.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:03:06 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:06 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:14 +0330] "GET /wp-includes/bk/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:29 +0330] "GET /wp-includes/block-bindings/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:29 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:29 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:30 +0330] "GET /wp-includes/blocks/shortcode/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:04 +0330] "GET /wp-content/w3tc/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:17 +0330] "GET /wp-content/cache/supercache/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:24 +0330] "GET /wp-content/wflogs/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:04:24 +0330] "GET /wp-content/updraft/ HTTP/1.1" 200 112 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:04:24 +0330] "GET /wp-content/ai1wm-backups/ HTTP/1.1" 500 26 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:25 +0330] "GET /wp-content/backups-dup-lite/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:30 +0330] "GET /wp-content/backup-db/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:35 +0330] "GET /wp-content/uploads/woocommerce_uploads/ HTTP/1.1" 200 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:35 +0330] "GET /wp-content/uploads/woocommerce/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:04:40 +0330] "GET /wp-content/uploads/wc-logs/ HTTP/1.1" 200 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:04:40 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:41 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:04:41 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 54.201.195.80 - - [30/Nov/2025:01:04:41 +0330] "GET / HTTP/1.1" 301 20 "-" "Python/3.12 aiohttp/3.12.15" 4.205.225.47 - - [30/Nov/2025:01:04:41 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:04:47 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 54.201.195.80 - - [30/Nov/2025:01:04:53 +0330] "GET / HTTP/1.1" 301 20 "-" "Python/3.12 aiohttp/3.12.15" 4.205.225.47 - - [30/Nov/2025:01:02:50 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:02:51 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:02:51 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.205.225.47 - - [30/Nov/2025:01:02:51 +0330] "GET /wp-includes/Text/Diff/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:03:39 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:39 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:03:40 +0330] "GET /wp-includes/css/dist/alam.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.205.225.47 - - [30/Nov/2025:01:03:47 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:48 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:03:56 +0330] "GET /wp-content/cache/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.205.225.47 - - [30/Nov/2025:01:04:10 +0330] "GET /wp-content/et-cache/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 43.135.140.225 - - [30/Nov/2025:01:04:36 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 104.236.93.174 - - [30/Nov/2025:01:47:44 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 95.68.128.245 - - [30/Nov/2025:01:43:53 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:49.0) Gecko/20100101 Firefox/49.0" 95.68.128.245 - - [30/Nov/2025:01:44:00 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2686.46 Safari/537.36" 4.241.208.113 - - [30/Nov/2025:01:46:37 +0330] "GET / HTTP/1.1" 403 17366 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:01:46:37 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17366 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:01:46:37 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17366 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:01:46:38 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17366 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:01:46:37 +0330] "POST /wp-plain.php HTTP/1.1" 404 102573 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:01:46:41 +0330] "GET /luifkodo.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 47.128.99.222 - - [30/Nov/2025:02:16:05 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 185.152.66.230 - - [30/Nov/2025:04:06:15 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" 222.79.104.23 - - [30/Nov/2025:04:17:53 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 81.199.26.20 - - [30/Nov/2025:05:25:50 +0330] "GET /.env HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 52.178.157.85 - - [30/Nov/2025:05:29:49 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 172.86.68.246 - - [30/Nov/2025:06:24:57 +0330] "GET /userfuns.php HTTP/1.1" 403 6889 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.86.68.246 - - [30/Nov/2025:06:24:58 +0330] "GET /postnews.php HTTP/1.1" 403 6888 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 43.157.38.228 - - [30/Nov/2025:06:26:37 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 194.5.82.92 - - [30/Nov/2025:06:35:12 +0330] "GET /manager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:35:14 +0330] "GET /bless.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:15 +0330] "GET /O-Simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:35:17 +0330] "GET /lock360.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:35:18 +0330] "GET /zwso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:20 +0330] "GET /chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:21 +0330] "GET /about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:23 +0330] "GET /admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:24 +0330] "GET /.well-known/login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:26 +0330] "GET /mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:35:27 +0330] "GET /.wp/wso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:29 +0330] "GET /core.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:35:31 +0330] "GET /robots.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:33 +0330] "GET /inputs.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:34 +0330] "GET /mini.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:35:36 +0330] "GET /goods.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:37 +0330] "GET /file5.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:39 +0330] "GET /ahax.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:35:41 +0330] "GET /f35.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.92 - - [30/Nov/2025:06:35:42 +0330] "GET /simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:35:44 +0330] "GET /update/f35.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:45 +0330] "GET /wp-content/hello.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:35:47 +0330] "GET /wp-admin/maint/bootstrap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:48 +0330] "GET /themes/zMousse/otuz1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.92 - - [30/Nov/2025:06:35:50 +0330] "GET /wp-content/edit-wolf.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:35:51 +0330] "GET /wp-content/plugins/ubh/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:35:53 +0330] "GET /wp-admin/images/bootstrap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:35:54 +0330] "GET /images/upload.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:35:55 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.92 - - [30/Nov/2025:06:35:57 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:35:59 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:00 +0330] "GET /admin/uploads/bn_1_1754420677.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:02 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:36:03 +0330] "GET /wp-content/plugins/pwnd/pwnd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:05 +0330] "GET /wp-content/plugins/pwnd-1/pwnd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:06 +0330] "GET /wp-admin/css/colors/midnight/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:08 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/kill.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:36:09 +0330] "GET /wp-includes/style-engine/worksec.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:36:11 +0330] "GET /wp-admin/images/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:12 +0330] "GET /wp-content/plugins/core-plugin/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:14 +0330] "GET /wp-content/plugins/envato-css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:36:15 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:36:17 +0330] "GET /uploads/94056-upload.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:19 +0330] "GET /index/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:20 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:36:22 +0330] "GET /js/bas.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:36:23 +0330] "GET /.well-known/pki-validation/moon.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:36:24 +0330] "GET /file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.92 - - [30/Nov/2025:06:36:25 +0330] "GET /wp-includes/js/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.92 - - [30/Nov/2025:06:36:27 +0330] "GET /wp-content/upgrade/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:29 +0330] "GET /buy.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:31 +0330] "GET /wp-content/languages/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:32 +0330] "GET /wp-content/themes/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:34 +0330] "GET /wp-content/plugins/elementor/wp-wjvngrh.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:36:35 +0330] "GET /wp-includes/IXR/fix.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:37 +0330] "GET /wp-includes/widgets/dyqvcfqv.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:39 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:40 +0330] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:42 +0330] "GET /wp-includes/js/crop/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:44 +0330] "GET /wp-includes/PHPMailer/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:45 +0330] "GET /wp-includes/PHPMailer/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:36:47 +0330] "GET /wp-includes/widgets/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:36:48 +0330] "GET /files/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:50 +0330] "GET /wp-includes/PHPMailer/options.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.92 - - [30/Nov/2025:06:36:51 +0330] "GET /inc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:53 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:54 +0330] "GET /filemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:55 +0330] "GET /cgi-bin/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:36:57 +0330] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:57 +0330] "GET /wp-includes/IXR/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:36:59 +0330] "GET /wp-admin/js/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:37:01 +0330] "GET /wp-includes/js/jquery/jquery.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:37:03 +0330] "GET /function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:37:04 +0330] "GET /wp-includes/block-supports/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:37:06 +0330] "GET /wp-signup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:37:07 +0330] "GET /wp-admin/network/network.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:09 +0330] "GET /admin/upload/css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:11 +0330] "GET /wp-blog.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:37:12 +0330] "GET /wp-admin/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:37:14 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:37:15 +0330] "GET /wp-includes/blocks/table/int/tmpl/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:17 +0330] "GET /wp-l0gin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:37:19 +0330] "GET /wp-includes/js/jquery/suggest.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:20 +0330] "GET /new.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:22 +0330] "GET /wp-content/plugins/pwnd-1/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:23 +0330] "GET /wp-includes/defaults.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:37:25 +0330] "GET /images/DJP9.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:27 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:28 +0330] "GET /wp-admin/shell20211028.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:30 +0330] "GET /natural.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:32 +0330] "GET /item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:33 +0330] "GET /function/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:37:35 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:36 +0330] "GET /wp-admin/images/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:37:38 +0330] "GET /wp-includes/theme-compat/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.92 - - [30/Nov/2025:06:37:39 +0330] "GET /about/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:41 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:42 +0330] "GET /wp-includes/ID3/about.php/wp-content/x/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:44 +0330] "GET /wp-includes/ID3/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:37:46 +0330] "GET /wp-content/languages/404.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:47 +0330] "GET /update/403.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:49 +0330] "GET /default.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:50 +0330] "GET /wp-includes/assets/info.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:52 +0330] "GET /wp-includes/class.api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:37:53 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:55 +0330] "GET /wp-admin/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:57 +0330] "GET /autoload_classmap/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:37:58 +0330] "GET /dropdown.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:38:00 +0330] "GET /images/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:01 +0330] "GET /db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:03 +0330] "GET /.well-known/pki-validation/mariju.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:38:03 +0330] "GET /mah/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:38:05 +0330] "GET /wp-content/plugins/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:07 +0330] "GET /wp-includes/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:08 +0330] "GET /wp-content/themes/tflow/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:38:10 +0330] "GET /wp-admin/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:38:12 +0330] "GET /templates/beez3/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:38:13 +0330] "GET /wp-admin/js/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:38:15 +0330] "GET /install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:38:16 +0330] "GET /wp-admin/css/colors/blue/rk2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.92 - - [30/Nov/2025:06:38:18 +0330] "GET /images/class-config.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:19 +0330] "GET /components/com_jea/views/form/tmpl/size.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:38:21 +0330] "GET /templates/beez/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:22 +0330] "GET /bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:38:24 +0330] "GET /class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:25 +0330] "GET /wp-admin/css/colors/light/profile.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:27 +0330] "GET /wp-content/product.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:29 +0330] "GET /wp-content/uploads/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:38:30 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ask.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:32 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:38:34 +0330] "GET /css/css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:35 +0330] "GET /init.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:37 +0330] "GET /wp-admin/user/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:38:38 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:38:40 +0330] "GET /wp-includes/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:41 +0330] "GET /assets/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:38:43 +0330] "GET /.well-known/pki-validation/index.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:38:43 +0330] "GET /wp-content/uploads/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:45 +0330] "GET /css/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:38:46 +0330] "GET /adminfuns.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:48 +0330] "GET /wp-admin/css/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:49 +0330] "GET /wp_wlx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:51 +0330] "GET /wp-admin/js/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:38:52 +0330] "GET /wp-includes/assets/husky301.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:38:54 +0330] "GET /wp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:38:56 +0330] "GET /wp-admin/css/colors/blue/wp-trackback.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:57 +0330] "GET /wp-content/themes/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:38:58 +0330] "GET /wp-header.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:00 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:39:02 +0330] "GET /Marvins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:03 +0330] "GET /wp-content/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:39:05 +0330] "GET /wp-class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:39:06 +0330] "GET /wp-includes/images/smilies/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:39:08 +0330] "GET /xx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:39:10 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:39:11 +0330] "GET /wp-includes/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:39:13 +0330] "GET /wp-content/blue.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:14 +0330] "GET /content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:39:16 +0330] "GET /wp-content/uploads/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:39:17 +0330] "GET /wp-admin/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:39:19 +0330] "GET /wp-includes/rest-api/endpoints/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:20 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:39:22 +0330] "GET /wp-content/plugins/wp-theme-editor/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:24 +0330] "GET /wp-content/plugins/up/main.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:25 +0330] "GET /fonts/fontawesome-webfont.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:27 +0330] "GET /wp-admin/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:39:29 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:39:30 +0330] "GET /wp-admin/css/colors/blue/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:39:32 +0330] "GET /images/images/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:33 +0330] "GET /images/class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:39:35 +0330] "GET /wp-content/plugins/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:39:37 +0330] "GET /web.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:38 +0330] "GET /wp-admin/css/colors/ocean/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:40 +0330] "GET /images/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:41 +0330] "GET /wp-content/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:39:43 +0330] "GET /.well-known/gecko-litespeed.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.92 - - [30/Nov/2025:06:39:44 +0330] "GET /wp-admin/css/colors/midnight/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:39:46 +0330] "GET /wp-trackback.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:47 +0330] "GET /wp-includes/style-engine/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:49 +0330] "GET /radio.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:39:50 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:39:52 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:53 +0330] "GET /wp-admin/css/colors/midnight/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:55 +0330] "GET /wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:39:56 +0330] "GET /wp-setup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:39:58 +0330] "GET /ms-themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:39:59 +0330] "GET /wp-includes/assets/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:40:01 +0330] "GET /style.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:40:03 +0330] "GET /wp-includes/infi.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:40:04 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:06 +0330] "GET /x.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:40:07 +0330] "GET /wp-includes/IXR/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:40:09 +0330] "GET /css/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:40:10 +0330] "GET /images/index22.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:12 +0330] "GET /wp-user.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:40:13 +0330] "GET /wp-includes/pomo/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:15 +0330] "GET /wp-includes/pomo/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:17 +0330] "GET /config.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:18 +0330] "GET /special.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:20 +0330] "GET /assets/script.js.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:21 +0330] "GET /wp-content/themes/twentytwentythree/patterns/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:23 +0330] "GET /wp-admin/css/colors/sunrise/colors_95.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:40:24 +0330] "GET /wp-includes/block-patterns/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:40:26 +0330] "GET /wp-content/uploads/wp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:28 +0330] "GET /wp-includes/certificates/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:40:29 +0330] "GET /cgi-bin/class.api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:40:31 +0330] "GET /wp-content/cache/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:32 +0330] "GET /wp-admin/css/colors/blue/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.92 - - [30/Nov/2025:06:40:34 +0330] "GET /wp-includes/edit.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:36 +0330] "GET /webdb.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:37 +0330] "GET /assets/images/doc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:40:39 +0330] "GET /file2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:40 +0330] "GET /wp-includes/ID3/wp-work.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:40:42 +0330] "GET /alfa.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:40:43 +0330] "GET /wp-admin/css/colors/blue/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:40:45 +0330] "GET /wp-includes/click.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:40:46 +0330] "GET /.well-known/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:40:48 +0330] "GET /wp-admin/css/colors/blue/atomlib.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:40:49 +0330] "GET /wp-admin/js/widgets/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:51 +0330] "GET /wp-includes/random_compat/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.92 - - [30/Nov/2025:06:40:53 +0330] "GET /wp-admin/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.92 - - [30/Nov/2025:06:40:54 +0330] "GET /edit.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:56 +0330] "GET /wp-content/plugins/WordPressCore/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:57 +0330] "GET /cgi-bin/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:40:59 +0330] "GET /wp-links-opml.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:41:01 +0330] "GET /wp-admin/user/network.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:03 +0330] "GET /atomlib.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:41:04 +0330] "GET /wp-includes/js/jquery/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:41:06 +0330] "GET /wp-includes/xl2023.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:41:07 +0330] "GET /wp-includes/certificates/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:41:09 +0330] "GET /wp-includes/images/media/dog.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:41:10 +0330] "GET /xp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:12 +0330] "GET /wp-includes/SimplePie/applicationd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:14 +0330] "GET /wp-includes/assets/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:41:16 +0330] "GET /wp-links.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:17 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:19 +0330] "GET /wp-includes/css/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 66.249.66.11 - - [30/Nov/2025:06:33:05 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.13 - - [30/Nov/2025:06:33:09 +0330] "GET /courses/gams_compressed HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 194.5.82.92 - - [30/Nov/2025:06:41:20 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:22 +0330] "GET /wp-includes/pomo/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:41:23 +0330] "GET /wp-includes/IXR/security.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:25 +0330] "GET /wp-content/plugins/phpadmin/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:41:27 +0330] "GET /wp-includes/Requests/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:41:28 +0330] "GET /wp-content/plugins/hello.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:41:30 +0330] "GET /wp-content/plugins/seoo/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:32 +0330] "GET /wp-includes/fonts/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:41:33 +0330] "GET /moon.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:41:35 +0330] "GET /wp-admin/user/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.92 - - [30/Nov/2025:06:41:37 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:39 +0330] "GET /webadmin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:40 +0330] "GET /wp-includes/PHPMailer/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:42 +0330] "GET /wp-admin/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.92 - - [30/Nov/2025:06:41:43 +0330] "GET /xl2023.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:45 +0330] "GET /go.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:46 +0330] "GET /wp-admin/xleet.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:41:48 +0330] "GET /templates/beez3/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:49 +0330] "GET /wp-admin/css/colors/blue/ahax.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:41:51 +0330] "GET /.well-known/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:52 +0330] "GET /wp-includes/assets/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:41:54 +0330] "GET /cgi-bin/index.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:54 +0330] "GET /wp-content/uploads/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:56 +0330] "GET /wp-content/plugins/view-more/ioxi.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:41:57 +0330] "GET /wp-includes/customize/dedi1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:41:59 +0330] "GET /wp-includes/pomo/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:42:01 +0330] "GET /wp-admin/css/colors/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:42:02 +0330] "GET /warm.PhP7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:42:04 +0330] "GET /wp-admin/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:05 +0330] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:07 +0330] "GET /wp-includes/images/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:08 +0330] "GET /wp-content/plugins/ioxi/ioxiworm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:10 +0330] "GET /blog/wp-content/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:42:11 +0330] "GET /hehehehe.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:13 +0330] "GET /.well-known/acme-challenge/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:42:14 +0330] "GET /.well-known/acme-challenge/plugins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:16 +0330] "GET /.well-known/acme-challenge/license.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:17 +0330] "GET /wp-content/themes/astra/inc/ki1k.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:19 +0330] "GET /wp-content/themes/astra/inc/fm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:21 +0330] "GET /wp-content/plugins/ccx/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:42:22 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.92 - - [30/Nov/2025:06:42:24 +0330] "GET /wp-includes/Requests/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:42:25 +0330] "GET /wp-includes/css/dist/edit-widgets/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:27 +0330] "GET /wp-includes/css/dist/edit-widgets/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:42:28 +0330] "GET /wp-includes/Requests/src/Exception/Http/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:30 +0330] "GET /wp-includes/Text/Diff/Renderer/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:42:31 +0330] "GET /wp-includes/Text/Diff/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:33 +0330] "GET /wp-admin/css/colors/ocean/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:42:34 +0330] "GET /wp-includes/images/media/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:42:36 +0330] "GET /wp-includes/js/tinymce/skins/lightgray/img/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:42:37 +0330] "GET /wp-includes/js/tinymce/skins/lightgray/img/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:38 +0330] "GET /wp-includes/js/tinymce/skins/lightgray/img/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:42:40 +0330] "GET /wp-admin/maint/themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:42:42 +0330] "GET /wp-content/plugins/seoplugins/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:42:43 +0330] "GET /wp-includes/fonts/themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:42:44 +0330] "GET /wp-content/themes/twentytwentytwo/assets/fonts/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:46 +0330] "GET /wp-includes/certificates/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:47 +0330] "GET /byp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:49 +0330] "GET /blog/wp-includes/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:50 +0330] "GET /wp-includes/images/media/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:52 +0330] "GET /blog/wp-admin/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:42:53 +0330] "GET /wp-content/themes/twentyfive/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:54 +0330] "GET /wp-includes/css/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:56 +0330] "GET /cgi-bin/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:42:57 +0330] "GET /wp-content/wso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:42:59 +0330] "GET /class.api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:00 +0330] "GET /wp-includes/certificates/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:02 +0330] "GET /wp-content/radio.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:03 +0330] "GET /system_log.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:05 +0330] "GET /.alf.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:06 +0330] "GET /wso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:43:08 +0330] "GET /wp-includes/blocks/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:09 +0330] "GET /flower.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:43:10 +0330] "GET /wp-includes/wp-class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:43:12 +0330] "GET /wp-admin/js/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:14 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:43:15 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:17 +0330] "GET /info.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:18 +0330] "GET /setup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:20 +0330] "GET /.bod/.ll/ss.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:21 +0330] "GET /.well-known/radio.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:23 +0330] "GET /wp-content/plugin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:24 +0330] "GET /wp-admin/css/colors/ectoplasm/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:25 +0330] "GET /as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:43:27 +0330] "GET /cc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:28 +0330] "GET /.well-known/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:43:30 +0330] "GET /ab.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:43:31 +0330] "GET /wp-content/themes/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:33 +0330] "GET /wp-content/themes/twentytwentytwo/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:34 +0330] "GET /doc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:36 +0330] "GET /wp-includes/html-api/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:37 +0330] "GET /wp-includes/style-engine/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:43:39 +0330] "GET /wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:40 +0330] "GET /mar.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:42 +0330] "GET /wp-includes/sitemaps/providers/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:43 +0330] "GET /wp-admin/css/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:43:45 +0330] "GET /1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:47 +0330] "GET /wp-includes/Text/Diff/Engine/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:48 +0330] "GET /wp-includes/style-engine/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:50 +0330] "GET /js/fm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:51 +0330] "GET /wp-admin/images/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:43:53 +0330] "GET /wp-content/uploads/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:43:54 +0330] "GET /wp-content/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:43:56 +0330] "GET /wp-includes/Text/Diff/Engine/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:57 +0330] "GET /fm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:43:59 +0330] "GET /wp-admin/js/widgets/cloud.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:44:01 +0330] "GET /adminfuns.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:44:02 +0330] "GET /wp-admin/images/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:44:03 +0330] "GET /ini.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:44:05 +0330] "GET /wp-admin/css/colors/coffee/cloud.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:07 +0330] "GET /wp-includes/blocks/calendar/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:44:08 +0330] "GET /admin/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:44:09 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:11 +0330] "GET /.well-known/acme-challenge/atomlib.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:12 +0330] "GET /wp-admin/js/instaall.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:44:13 +0330] "GET /wp-includes/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:44:15 +0330] "GET /wp-includes/plugins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:44:17 +0330] "GET /wp-content/plugins/atomlib.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:44:18 +0330] "GET /wp-content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:20 +0330] "GET /wp-includes/css/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:44:21 +0330] "GET /wp-includes/Text/Diff/Renderer/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:23 +0330] "GET /wp-admin/network/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:44:25 +0330] "GET /wp-admin/css/colors/light/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:44:26 +0330] "GET /customize.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:28 +0330] "GET /license.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:29 +0330] "GET /wp-content/languages/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:44:31 +0330] "GET /lock.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.92 - - [30/Nov/2025:06:44:32 +0330] "GET /wp-admin/css/colors/blue/gold.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:44:34 +0330] "GET /wp-includes/atomlib.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:44:34 +0330] "GET /wp-includes/rest-api/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:36 +0330] "GET /.well-known/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:44:38 +0330] "GET /.well-known/wincust.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:39 +0330] "GET /wp-admin/css/colors/light/alfa-rex.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:44:41 +0330] "GET /wp-good.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:42 +0330] "GET /wp-includes/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:43 +0330] "GET /wp-includes/style-engine/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:45 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:46 +0330] "GET /wp-content/themes/twentytwentyfour/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:48 +0330] "GET /randkeyword.PhP7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:49 +0330] "GET /wp-admin/js/widgets/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:51 +0330] "GET /fonts/database.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:52 +0330] "GET /ff2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:44:54 +0330] "GET /wp-includes/SimplePie/Exception-wp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:44:55 +0330] "GET /wp-admin/plugin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:44:57 +0330] "GET /wp-includes/rest-api/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:44:59 +0330] "GET /jp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:00 +0330] "GET /wp-atom.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:45:02 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.92 - - [30/Nov/2025:06:45:04 +0330] "GET /up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:05 +0330] "GET /wp-content/uploads/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:45:07 +0330] "GET /assets/images/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:08 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.92 - - [30/Nov/2025:06:45:09 +0330] "GET /js/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:11 +0330] "GET /simple/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:12 +0330] "GET /worm.PhP HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:45:14 +0330] "GET /ext.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:15 +0330] "GET /delpaths.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:45:17 +0330] "GET /.well-known/pki-validation/1.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:17 +0330] "GET /wp-includes/bk/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:19 +0330] "GET /wp-content/plugins/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:21 +0330] "GET /.well-known/pki-validation/install.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:21 +0330] "GET /wp-admin/css/colors/sunrise/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:23 +0330] "GET /gifclass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:24 +0330] "GET /plugin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:45:26 +0330] "GET /wp-content/themes/twentytwentyfour/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:45:27 +0330] "GET /update-core.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:45:29 +0330] "GET /wp-admin/css/colors/blue/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:31 +0330] "GET /wp-mail.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:32 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:45:34 +0330] "GET /wp-admin/defaults.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:35 +0330] "GET /.well-known/acme-challenge/content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:45:36 +0330] "GET /wp-content/ALFA_DATA/alfacgiapi/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:38 +0330] "GET /wp-admin/maint/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:45:40 +0330] "GET /wp-admin/js/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.92 - - [30/Nov/2025:06:45:42 +0330] "GET /wp-content/uploads/2023/05/404.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:45:43 +0330] "GET /wp-admin/maint/maint.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:45 +0330] "GET /assets/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:45:46 +0330] "GET /aa.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:45:48 +0330] "GET /index2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:49 +0330] "GET /wp-content/themes/hello-element/footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:51 +0330] "GET /wp-admin/network/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:52 +0330] "GET /.well-known/pki-validation/2index.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:53 +0330] "GET /wp-content/languages/plugins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:45:54 +0330] "GET /shell.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:56 +0330] "GET /.well-known/content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:45:58 +0330] "GET /wp-includes/Text/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:45:59 +0330] "GET /wp-admin/network/atomlib.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:01 +0330] "GET /.well-known/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:46:02 +0330] "GET /hehe.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:04 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:05 +0330] "GET /css/slider.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:07 +0330] "GET /dir.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:46:09 +0330] "GET /wp-includes/css/atomlib.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:46:10 +0330] "GET /wp-content/style.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:46:11 +0330] "GET /libraries/phpmailer/updates.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:13 +0330] "GET /nf_tracking.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:46:15 +0330] "GET /wp-admin/css/about.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:46:16 +0330] "GET /filefuns.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:46:18 +0330] "GET /.well-known/pki-validation/class_api.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:18 +0330] "GET /l.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:46:19 +0330] "GET /repeater.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:21 +0330] "GET /wp-admin/wso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:22 +0330] "GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:46:24 +0330] "GET /contacts.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:25 +0330] "GET /wsa.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:46:27 +0330] "GET /wp-includes/SimplePie/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:46:28 +0330] "GET /firewall.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:46:29 +0330] "GET /wp-includes/sodium_compat/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:31 +0330] "GET /wp-content/uploads/content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:33 +0330] "GET /lv.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:46:34 +0330] "GET /images/js1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:46:36 +0330] "GET /wp-admin/maint/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:37 +0330] "GET /.well-known/acme-challenge/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:39 +0330] "GET /.well-known/acme-challenge/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:46:40 +0330] "GET /wp-includes/images/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:42 +0330] "GET /wp-includes/ID3/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:43 +0330] "GET /wp-admin/theme-editor.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:46:45 +0330] "GET /wp-admin/css/colors/blue/abc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:46 +0330] "GET /wp-admin/maint/wonder.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:48 +0330] "GET /wp-content/themes/twentytwentyfour/wonder.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:49 +0330] "GET /wp-content/plugins/fix/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:51 +0330] "GET /tox.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:46:52 +0330] "GET /wp-content/languages/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:53 +0330] "GET /wp-includes/js/dist/default.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:55 +0330] "GET /wp-admin/css/colors/tfileman.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:56 +0330] "GET /tiny.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:46:58 +0330] "GET /wp-admin/js/widgets/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:46:59 +0330] "GET /themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:47:01 +0330] "GET /wp-themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:03 +0330] "GET /wp-includes/sodium_compat/src/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:04 +0330] "GET /wp-content/plugins/erinyani/asasx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:05 +0330] "GET /mariju.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:07 +0330] "GET /waf_defender.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:08 +0330] "GET /wp-admin/maint/cong.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:47:10 +0330] "GET /av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:47:11 +0330] "GET /wp-admin/css/glex.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:47:13 +0330] "GET /wp-admin/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:47:14 +0330] "GET /wp-includes/SimplePie/Parse/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:15 +0330] "GET /.well-known/acme-challenge/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:17 +0330] "GET /wp-content/themes/twentytwentyfour/system_cache.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.92 - - [30/Nov/2025:06:47:18 +0330] "GET /wp-content/themes/sky-pro/js.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:20 +0330] "GET /wp-includes/Text/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:21 +0330] "GET /wp-content/themes/pridmag/waf_defender.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:23 +0330] "GET /theme.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:25 +0330] "GET /wp-content/themes/twentytwentytwo/waf_defender.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:26 +0330] "GET /wp-admin/css/colors/coffee/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:47:28 +0330] "GET /Simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:47:29 +0330] "GET /.well-known/acme-challenge/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:31 +0330] "GET /wp-admin/1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:33 +0330] "GET /wp-admin/css/colors/ocean/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:47:34 +0330] "GET /wp-content/plugins/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:35 +0330] "GET /.well-known/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.92 - - [30/Nov/2025:06:47:37 +0330] "GET /css/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:39 +0330] "GET /images/waf_defender.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:40 +0330] "GET /wp-includes/SimplePie/Cache/upfile.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:42 +0330] "GET /small.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:47:43 +0330] "GET /wp-includes/js/tinymce/plugins/fullscreen/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:45 +0330] "GET /NewFile.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:46 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:47:48 +0330] "GET /error.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:47:49 +0330] "GET /wp-content/plugins/pwnd/admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:51 +0330] "GET /wp-includes/widgets/class-wp-widget-search-function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:47:52 +0330] "GET /wp-content/languages/themes/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:54 +0330] "GET /wp-files.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:47:55 +0330] "GET /functions.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:47:57 +0330] "GET /admin/controller/extension/extension/cloud.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:47:58 +0330] "GET /wp-includes/SimplePie/Canonical.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.92 - - [30/Nov/2025:06:48:00 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/uss.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:01 +0330] "GET /wp-includes/certificates/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:03 +0330] "GET /aks.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:48:04 +0330] "GET /litespeed.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:48:06 +0330] "GET /img/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.92 - - [30/Nov/2025:06:48:07 +0330] "GET /wp-includes/class-feed-index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:48:09 +0330] "GET /wpn.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:48:10 +0330] "GET /wp-content/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:12 +0330] "GET /.well-known/acme-challenge/iR7SzrsOUEP.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:13 +0330] "GET /wp-includes/customize/class-wp-customize-nav-menu-section-boolean.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:48:15 +0330] "GET /wp-content/themes/twentytwentyfour/functions.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:16 +0330] "GET /wp-includes/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:18 +0330] "GET /wp-includes/class-wp-dependency-float.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:48:19 +0330] "GET /wp-includes/PHPMailer/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:21 +0330] "GET /wp-includes/PHPMailer/purna.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:48:22 +0330] "GET /wp-includes/interactivity-api/interactivity-api-class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:24 +0330] "GET /wp-includes/l10n/class-wp-widddget-pages.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:25 +0330] "GET /tinyfilemanager/tinyfilemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.92 - - [30/Nov/2025:06:48:27 +0330] "GET /wp-admin/css/colors/light/colors.min.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:29 +0330] "GET /wp-includes/customize/class-wp-customize-nav-menu-auto-add-control-repository.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:48:31 +0330] "GET /wp-includes/assets/script-loader-react-refresh-runtime.min-soap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:33 +0330] "GET /wp-includes/ID3/module.audio-video.riff-set.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:34 +0330] "GET /fog/management/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:36 +0330] "GET /wp-includes/js/tinymce/utils/license.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:37 +0330] "GET /components/com_newsfeeds/models/indexx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:48:39 +0330] "GET /images/wp-aespa.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.92 - - [30/Nov/2025:06:48:40 +0330] "GET /wp-includes/Text/options.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:48:42 +0330] "GET /.well-known/acme-challenge/wp-load.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:43 +0330] "GET /wp-content/upgrade/cc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:48:45 +0330] "GET /wp-content/themes/aahana/worksec.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:46 +0330] "GET /anonse/lock360.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.92 - - [30/Nov/2025:06:48:48 +0330] "GET /wp-content/themes/bltm/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:48:49 +0330] "GET /wp-admin/includes/class_api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:51 +0330] "GET /plugins/content/apismtp/apismtp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:52 +0330] "GET /wp-admin/includes/class-core-upgrader-first.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:48:54 +0330] "GET /wp-admin/css/wp-css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:55 +0330] "GET /.well-known/save.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:56 +0330] "GET /wp-includes/feed-rsss.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:48:58 +0330] "GET /wp-includes/IXR/goto.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:48:59 +0330] "GET /wp-admin/css/colors/blue/xboom.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:01 +0330] "GET /uploads/af32.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:03 +0330] "GET /wp-content/themes/kadence/functions.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.92 - - [30/Nov/2025:06:49:04 +0330] "GET /Sanskrit.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:06 +0330] "GET /wp-fmfile.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:07 +0330] "GET /.trash7309/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:09 +0330] "GET /wp-content/plugins/revslider/includes/external/page/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:49:10 +0330] "GET /wp-content/plugins/ioxi/ioxi/dropdown.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.92 - - [30/Nov/2025:06:49:12 +0330] "GET /memberfuns.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:49:13 +0330] "GET /infos.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:15 +0330] "GET /modules/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:49:17 +0330] "GET /wp-content/x.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:49:18 +0330] "GET /wp-content/wp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:49:20 +0330] "GET /options-writing.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:21 +0330] "GET /options-reading.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:22 +0330] "GET /wsad.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.92 - - [30/Nov/2025:06:49:24 +0330] "GET /nation.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.92 - - [30/Nov/2025:06:49:25 +0330] "GET /wp-includes/js/codemirror/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:27 +0330] "GET /wp-includes/wp_class_datlib.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:37 +0330] "GET /wp-content/plugins/ubh/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:49:39 +0330] "GET /wp-includes/SimplePie/Registry-private.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:41 +0330] "GET /wp-includes/assets/script-modules-packages.min-meta.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:49:42 +0330] "GET /wp-includes/widgets/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:44 +0330] "GET /wp-content/themes/twentytwentyfour/content-index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:45 +0330] "GET /admin/controller/extension/extension/alfa.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:47 +0330] "GET /wp-content/themes/twentytwentyfour/system_cache.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:49:48 +0330] "GET /wp-admin/css/colors/modern/colors.css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:50 +0330] "GET /wp-includes/style-engine/adminfus.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:51 +0330] "GET /css/media-widget-vide02.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:49:53 +0330] "GET /wp-includes/blocks/group/wp-style.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:49:54 +0330] "GET /images/buy.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:06:49:56 +0330] "GET /templates/beez3/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:57 +0330] "GET /wp-includes/widgets/class-wp-wolf-widget.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:49:59 +0330] "GET /wp-admin/css/colors/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:00 +0330] "GET /plugins/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:02 +0330] "GET /.well-known/header.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:06:50:04 +0330] "GET /wordpress/wp-content/uploads/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:05 +0330] "GET /.well-known/pki-validation/server.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:06 +0330] "GET /autoload_classmap/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:06:50:07 +0330] "GET /wp-content/plugins/pwnd/1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:50:09 +0330] "GET /wp-content/plugins/ubh/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:06:50:10 +0330] "GET /wp-content/uploads/anas.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:50:12 +0330] "GET /wp-admin/css/colors/blue/shell.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:13 +0330] "GET /wp-content/plugins/erinyani/default.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:50:15 +0330] "GET /wp-includes/Text/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:06:50:16 +0330] "GET /xex.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:06:50:18 +0330] "GET /ar/wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:19 +0330] "GET /wp-includes/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:21 +0330] "GET /wp-content/plugins/pwnd/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:06:50:22 +0330] "GET /upload/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:24 +0330] "GET /wp-head.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:25 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:27 +0330] "GET /wp-content/upgrade/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:28 +0330] "GET /makeasmtp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:06:50:30 +0330] "GET /wp-includes/wp-sup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:50:32 +0330] "GET /wordpress/wp-includes/class-wp-http-ixr-client-view.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:50:33 +0330] "GET /images/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:35 +0330] "GET /wp-includes/widgets/class-t.api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:36 +0330] "GET /wp-content/edit.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:06:50:37 +0330] "GET /.well-known/info.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:39 +0330] "GET /wp-content/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:06:50:40 +0330] "GET /wp-admin/css/colors/blue/navi.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:42 +0330] "GET /wp-includes/css/dist/require-dynamic-blocks.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:43 +0330] "GET /xp.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:50:45 +0330] "GET /wp-content/languages/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:46 +0330] "GET /wp-content/bypass_1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:06:50:48 +0330] "GET /wp-admin/js/elementskit.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:50 +0330] "GET /admin/user_data.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:50:51 +0330] "GET /wp-includes/widgets/class-wp-widget-rss-database.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:53 +0330] "GET /.well-known/pki-validation/kur.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:53 +0330] "GET /click.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:55 +0330] "GET /wp-includes/class-wp-customize-manager-client.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:50:56 +0330] "GET /wp-includes/assets/script-modules-packages.min-boolean.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:50:58 +0330] "GET /wp-admin/css/colors/error.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:00 +0330] "GET /ALFA_DATA/alfacgiapi/all.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:01 +0330] "GET /wp-admin/images/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:51:03 +0330] "GET /.well-known/pki-validation/xmrlpc.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:03 +0330] "GET /wp-admin/maint/repairs.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:51:04 +0330] "GET /wp-includes/images/smilies/simi.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:51:06 +0330] "GET /wp-admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:06:51:08 +0330] "GET /wp-header.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:09 +0330] "GET /file.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:10 +0330] "GET /.tmb/doc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:51:12 +0330] "GET /wp-editor.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:13 +0330] "GET /wp-includes/style-engine-session.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:15 +0330] "GET /images/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:17 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/adminfusm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:18 +0330] "GET /adminfusm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:19 +0330] "GET /js/js1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:21 +0330] "GET /wp-includes/assets/wp-includes/assets/script-loader-packages.min.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:51:23 +0330] "GET /wp-includes/blocks/file/wp-style.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:24 +0330] "GET /images/habhan.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:51:25 +0330] "GET /wp-content/mu-plugins/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:27 +0330] "GET /wp-includes/IXR/class-IXR-cilent.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:28 +0330] "GET /wp-content/uploads/wp-cert.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:30 +0330] "GET /about/function.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:06:51:31 +0330] "GET /routes/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:33 +0330] "GET /wp-includes/images/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:34 +0330] "GET /wp-includes/PHPMailer/xleet.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:51:36 +0330] "GET /wp-admin/js/widgets/doc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:06:51:37 +0330] "GET /f35_SpaceTn.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:39 +0330] "GET /wp-admin/css/colors/sunrise/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:40 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/fixed.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:42 +0330] "GET /wp-admin/js/widgets/themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:51:43 +0330] "GET /wp-content/plugins/fix/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:06:51:45 +0330] "GET /wp-includes/category-double.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.81 - - [30/Nov/2025:06:51:46 +0330] "GET /wp-admin/maint/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:48 +0330] "GET /blog/signatur.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:51:49 +0330] "GET /wp-includes/assets/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:50 +0330] "GET /wp-includes/widgets/security.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:06:51:52 +0330] "GET /include/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:53 +0330] "GET /gm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:55 +0330] "GET /wp-includes/class-wp-language-pack.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:51:56 +0330] "GET /js/content-type.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:58 +0330] "GET /wp-includes/class-walker-comment-client.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:51:59 +0330] "GET /about/goods.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:52:01 +0330] "GET /file/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:02 +0330] "GET /function/goods.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:06:52:04 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:05 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:52:07 +0330] "GET /wp-includes/class-wp-network-query-stat.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:52:08 +0330] "GET /wp-content/themes/pridmag/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:10 +0330] "GET /plugin-install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:11 +0330] "GET /wp-includes/class-wp-session-tokens-https.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:13 +0330] "GET /wp-admin/js/load.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:14 +0330] "GET /images/firewall.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:52:16 +0330] "GET /wp-includes/images/crystal/lrs_dage.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:52:17 +0330] "GET /wp-content/upgrade/pdf.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:06:52:19 +0330] "GET /wp-includes/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:21 +0330] "GET /wp-content/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:52:22 +0330] "GET /wp-includes/certificates/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:52:24 +0330] "GET /wp-includes/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:52:25 +0330] "GET /wp-includes/customize/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:52:27 +0330] "GET /css/fan.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:52:28 +0330] "GET /wp-admin/css/colors/blue/colors.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:30 +0330] "GET /images/mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:52:31 +0330] "GET /wp-content/waf_defender.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:52:33 +0330] "GET /wp-admin/css/colors/ectoplasm/content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:52:34 +0330] "GET /wp-content/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:36 +0330] "GET /wp-includes/js/thickbox/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:37 +0330] "GET /wp-content/content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:39 +0330] "GET /wp-content/themes/twentytwentyfour/icascreenshots.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:40 +0330] "GET /wp-content/upgrade/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:42 +0330] "GET /wp-includes/rk2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:43 +0330] "GET /wp-admin/css/colors/ocean/alam.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:45 +0330] "GET /.well-known/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:46 +0330] "GET /b.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:48 +0330] "GET /wp-includes/certificates/past.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:49 +0330] "GET /wp-content/uploads/2021/faiyy.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:51 +0330] "GET /css/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:52 +0330] "GET /wp-content/plugins/pwnd/sst.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:52:54 +0330] "GET /wp-includes/edit-tags.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:52:55 +0330] "GET /wsax.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:52:57 +0330] "GET /bless.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:06:52:58 +0330] "GET /wp-content/uploads/system_cache.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:00 +0330] "GET /templates/beez3/dbcthbohhr.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:01 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/files.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:03 +0330] "GET /wp-content/themes/tflow/admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:06:53:04 +0330] "GET /wp-includes/css/dist/footer-default.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:06 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:07 +0330] "GET /wp-includes/widgets/class-wp-widget-meta-request.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:09 +0330] "GET /wp-content/plugins/pwnd/cloud.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:11 +0330] "GET /wp-includes/css/dist/edit-widgets/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:53:12 +0330] "GET /wp-content/plugins/ubh/adminfus.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:53:14 +0330] "GET /.well-known/pki-validation/webdb.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:53:14 +0330] "GET /wp-includes/l10n/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:16 +0330] "GET /wp-admin/js/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:17 +0330] "GET /wp-admin/js/widgets/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:19 +0330] "GET /uploads/xsec.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:20 +0330] "GET /images/Marvins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:22 +0330] "GET /wp-content/plugins/pwnd-1/kurd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:53:23 +0330] "GET /wp-content/themes/tflow/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:25 +0330] "GET /wp-content/languages/radio.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:53:26 +0330] "GET /wp-content/uploads/fileman.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:53:28 +0330] "GET /wp-includes/widgets/wp-ss.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:53:29 +0330] "GET /wp-includes/IXR/xsec1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:53:31 +0330] "GET /admin.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:32 +0330] "GET /wp-admin/css/colors/hong1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:53:34 +0330] "GET /wp-admin/maint/byps.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:36 +0330] "GET /wp-includes/images/crystal/sad.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:53:37 +0330] "GET /wp-includes/assets/script-loader-packages.min.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:38 +0330] "GET /wp-content/themes/twentytwentyfour/patterns/content-type.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:39 +0330] "GET /wp-admin/network/class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:41 +0330] "GET /wp-includes/class-phpmailer-beta.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:42 +0330] "GET /wp-includes/ms-file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:44 +0330] "GET /.well-known/acme-challenge/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:45 +0330] "GET /wp-includes/widgets/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:47 +0330] "GET /images/news_event/1.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:49 +0330] "GET /chosen.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:53:50 +0330] "GET /bs1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:06:53:52 +0330] "GET /wp-includes/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:06:53:53 +0330] "GET /wp-includes/network.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:53:55 +0330] "GET /page.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:56 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:53:58 +0330] "GET /wp-content/uploads/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:53:59 +0330] "GET /wp-content/plugins/WordPressCore/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:00 +0330] "GET /wp-content/admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:54:02 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:54:03 +0330] "GET /assets/info.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:54:05 +0330] "GET /wp-includes/SimplePie/XML/content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:54:06 +0330] "GET /wp-includes/pomo/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:08 +0330] "GET /wp-content/1.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:54:09 +0330] "GET /wp-admin/css/colors/blue/wp-atom.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:54:11 +0330] "GET /wp-includes/pomo/plugins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:54:13 +0330] "GET /wp-includes/assets/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:54:14 +0330] "GET /.well-known/acme-challenge/gecko-old.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:16 +0330] "GET /wp-admin/css/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:06:54:17 +0330] "GET /images/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:19 +0330] "GET /wp-includes/widgets/class-wp-nav-widgets.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:54:20 +0330] "GET /x/test.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:21 +0330] "GET /wp-content/themes/wp-pridmag/init.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:23 +0330] "GET /wp-admin/install.php HTTP/1.1" 403 17364 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:23 +0330] "GET /wp-admin/css/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:25 +0330] "GET /wp-includes/sitemaps/providers/doc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:27 +0330] "GET /ws.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:28 +0330] "GET /wp-includes/rest-api/1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:54:29 +0330] "GET /wp-includes/fonts/class_api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:31 +0330] "GET /shop.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:33 +0330] "GET /wp-content/plugins/pwnd-1/dedi1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:34 +0330] "GET /wp-admin/js/widgets/setting.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:36 +0330] "GET /wp-includes/images/smilies/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:54:37 +0330] "GET /wp-admin/css/colors/light/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:39 +0330] "GET /wp-admin/user/header.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:40 +0330] "GET /wp-includes/IXR/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:41 +0330] "GET /wp-api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:54:43 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:45 +0330] "GET /css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:46 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:54:47 +0330] "GET /wp-includes/class-wp-customize-manager-interpreter.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:54:49 +0330] "GET /wp-includes/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:50 +0330] "GET /images/fm.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:54:52 +0330] "GET /wp-includes/count.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:53 +0330] "GET /wp-error_log.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:55 +0330] "GET /assets/class_update_plugins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:56 +0330] "GET /wp-admin/network/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:54:58 +0330] "GET /templates/beez5/error.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:54:59 +0330] "GET /wp-admin/network/admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:01 +0330] "GET /js/firewall.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:55:03 +0330] "GET /wp-includes/certificates/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:04 +0330] "GET /assets/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:05 +0330] "GET /wp-admin/js/file/incpb.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:55:07 +0330] "GET /images/stories/themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:06:55:08 +0330] "GET /wp-includes/theme-compat/footer-embed-function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:10 +0330] "GET /wp-includes/firewall.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:06:55:11 +0330] "GET /home/O-Simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:13 +0330] "GET /wp-includes/l10n/class-wp-translation-file-mo-event.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:55:14 +0330] "GET /wp-includes/vars-soap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:16 +0330] "GET /wp-content/themes/twentytwentytwo/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:55:17 +0330] "GET /style.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:18 +0330] "GET /files.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:06:55:20 +0330] "GET /wp-content/themes/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:06:55:21 +0330] "GET /wp-admin/css/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:55:23 +0330] "GET /saka.phP7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:55:24 +0330] "GET /wp-includes/id3/wp-work.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:06:55:25 +0330] "GET /wp-content/plugins/WordPressCore/gecko.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:27 +0330] "GET /baxa1.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.81 - - [30/Nov/2025:06:55:28 +0330] "GET /wp-includes/class-wp-taxonomy.editor.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:55:30 +0330] "GET /wp-content/plugins/pwnd/dedi1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:31 +0330] "GET /wp-includes/js/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:33 +0330] "GET /blog.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:34 +0330] "GET /about/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:36 +0330] "GET /wp-content/themes/pridmag/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:55:37 +0330] "GET /wp-admin/network/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:06:55:38 +0330] "GET /images/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:40 +0330] "GET /wp-includes/interactivity-api/interactivity-api-xml.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:55:41 +0330] "GET /js/mrx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:43 +0330] "GET /wp-includes/colour.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:55:44 +0330] "GET /elp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:46 +0330] "GET /wp-includes/customize/class-wp-customize-background-position-control-variable.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:47 +0330] "GET /wp-includes/images/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:55:49 +0330] "GET /wp-content/themes/av.php.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:06:55:50 +0330] "GET /wp-content/plugins/pwnd-1/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:51 +0330] "GET /wp-includes/js/imgareaselect/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:55:53 +0330] "GET /upload/bilder/cong.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:55:54 +0330] "GET /fonts/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:55:56 +0330] "GET /wp-admin/css/colors/blue/pass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:06:55:57 +0330] "GET /entrepreneuse.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:55:59 +0330] "GET /wp-includes/l10n/class-wp-translations-interface.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:01 +0330] "GET /wp-includes/assets/about5.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:56:02 +0330] "GET /wp-admin/maint/lint-branch.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:04 +0330] "GET /wp-content/cong.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:56:05 +0330] "GET /js/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:07 +0330] "GET /.well-known/buy.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:08 +0330] "GET /index/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:56:10 +0330] "GET /wp-includes/ID3/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:56:11 +0330] "GET /function/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:56:13 +0330] "GET /wp-content/themes/tflow/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:56:14 +0330] "GET /wp-includes/js/dist/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:06:56:16 +0330] "GET /testt.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:56:17 +0330] "GET /wp-content/uploads/goods.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:56:18 +0330] "GET /wp-admin/js/sad.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:20 +0330] "GET /wp-includes/sitemaps/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:56:22 +0330] "GET /wp-includes/assets/wp-includes/assets/script-loader-packages.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:06:56:23 +0330] "GET /web/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:25 +0330] "GET /wp-includes/SimplePie/login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:56:26 +0330] "GET /network.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:56:28 +0330] "GET /wp-admin/css/colors/blue/alfa.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:06:56:29 +0330] "GET /wp-includes/sitemaps/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:31 +0330] "GET /wikindex.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:32 +0330] "GET /wp-content/plugins/seoo/alfa.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:34 +0330] "GET /wp-includes/SimplePie/Cache/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:56:35 +0330] "GET /wp-includes/css/dist/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:06:56:37 +0330] "GET /wp-content/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:38 +0330] "GET /wp-includes/customize/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:56:40 +0330] "GET /wp-includes/js/simi.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:06:56:41 +0330] "GET /wp-admin/images/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:06:56:43 +0330] "GET /wp-admin/css/colors/gold.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:56:45 +0330] "GET /wp-includes/Requests/Text/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:56:46 +0330] "GET /wp-content/mu-plugins/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:56:48 +0330] "GET /wp-includes/sitemaps/abcd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:49 +0330] "GET /wp-includes/ID3/rk2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:56:51 +0330] "GET /wp-includes/widgets/class-wp-widget-search-interpreter.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:56:52 +0330] "GET /wp-admin/css/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:54 +0330] "GET /bitrix/admin/htmleditor2/natural.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:55 +0330] "GET /wp-content/plugins/pwnd/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:57 +0330] "GET /wp-includes/block-template-utils-other.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:56:58 +0330] "GET /wp-content/alam.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:56:59 +0330] "GET /css/adminfusm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:57:01 +0330] "GET /wp-includes/sodium_compat/lib/widget-group.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:57:03 +0330] "GET /wp-content/raw.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:05 +0330] "GET /wp-includes/js/jcrop/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:06 +0330] "GET /wp-admin/includes/admin.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:07 +0330] "GET /wp-includes/customize/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:57:08 +0330] "GET /wp-content/uploads/2021/wp-works.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:10 +0330] "GET /wp-admin/media-new.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:11 +0330] "GET /media-new.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:13 +0330] "GET /js/class_api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:57:14 +0330] "GET /wp-content/uploads/2021/themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:06:57:16 +0330] "GET /admin/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:17 +0330] "GET /wp-includes/plugin.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:18 +0330] "GET /wp-includes/class-wp-scripts-query.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:57:20 +0330] "GET /wp-admin/js/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:06:57:21 +0330] "GET /pages.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:23 +0330] "GET /wp-includes/ID3/module.audio-license.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:06:57:25 +0330] "GET /wp-content/themes/classwithtostring.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:26 +0330] "GET /uploads/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:27 +0330] "GET /assets/js/doc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:57:29 +0330] "GET /assets/comfunctions.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:57:31 +0330] "GET /wp-includes/class-wp-error-module.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:57:32 +0330] "GET /css/adminfus.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:57:34 +0330] "GET /adminfus.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:35 +0330] "GET /wp-includes/css/litespeed.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:37 +0330] "GET /images/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:38 +0330] "GET /wp-admin/setup-config.php HTTP/1.1" 409 2838 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:39 +0330] "GET /wp-includes/css/dist/alam.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:41 +0330] "GET /cong.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:42 +0330] "GET /wp-includes/block-bindings/imagess.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:06:57:44 +0330] "GET /wp-content/plugins/pwnd/adminfus.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:45 +0330] "GET /wp-includes/default-filters-edit.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:47 +0330] "GET /css/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:48 +0330] "GET /assets/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:06:57:50 +0330] "GET /autoload_classmap/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:51 +0330] "GET /wp-configs.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:53 +0330] "GET /wp-includes/Requests/Auth/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:06:57:54 +0330] "GET /wp-admin/js/widgets/bless2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:57:56 +0330] "GET /wp-admin/network/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:57 +0330] "GET /wp-admin/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:57:59 +0330] "GET /wp-includes/Text/Diff/Engine/theme.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:01 +0330] "GET /.well-known/acme-challenge/mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:02 +0330] "GET /wp-includes/ID3/shell.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:04 +0330] "GET /wp-includes/customize/class-wp-customize-selective-refresh-library.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:05 +0330] "GET /ms-users.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:07 +0330] "GET /wp-admin/js/cc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:09 +0330] "GET /wp-includes/Requests/library/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.92 - - [30/Nov/2025:06:49:28 +0330] "GET /wp-includes/js/tinymce/langs/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:30 +0330] "GET /autoload_classmap/wso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.92 - - [30/Nov/2025:06:49:32 +0330] "GET /wp-atomx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.92 - - [30/Nov/2025:06:49:33 +0330] "GET /admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.92 - - [30/Nov/2025:06:49:34 +0330] "GET /wp-admin/maint/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:10 +0330] "GET /wp-includes/interactivity-api/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:58:12 +0330] "GET /css/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.81 - - [30/Nov/2025:06:58:13 +0330] "GET /wp-content/plugins/classic-editor/alam.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:15 +0330] "GET /wordpress/wp-admin/includes/wordpress/wp-admin/includes/admin-filters.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:16 +0330] "GET /assets/content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:58:18 +0330] "GET /fm.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:58:19 +0330] "GET /wp-content/goods.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:58:21 +0330] "GET /wp-includes/wp-2019.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:22 +0330] "GET /wp-includes/SimplePie/info.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:58:24 +0330] "GET /assets/images/cloud.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:26 +0330] "GET /wp-includes/log.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:27 +0330] "GET /wp-includes/assets/script-loader-react-refresh-runtime-num.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:58:29 +0330] "GET /wp-includes/assets/script-loader-react-refresh-entry.min-object.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:31 +0330] "GET /wp-includes/aw.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:32 +0330] "GET /update/gely.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:34 +0330] "GET /uploads/c99shell.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:06:58:35 +0330] "GET /wp-content/themes/pridmag/admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:06:58:37 +0330] "GET /uploads/lala.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:38 +0330] "GET /wp-includes/IXR/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:40 +0330] "GET /wp-includes/css/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.81 - - [30/Nov/2025:06:58:42 +0330] "GET /wp-content/plugins/wp-theme-editor/include.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:58:43 +0330] "GET /top.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:45 +0330] "GET /wp-includes/css/dist/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:46 +0330] "GET /wp-includes/style-engine/dedi1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:48 +0330] "GET /wp-admin/css/adminfusm.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:58:49 +0330] "GET /wp-content/click.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:06:58:51 +0330] "GET /wp-includes/template-less.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:58:53 +0330] "GET /wp-includes/pomo/alfa-rex.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:54 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/abcd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:58:56 +0330] "GET /wp-admin/css/colors/blue/admin-footer.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:57 +0330] "GET /retu11.PhP7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:58:59 +0330] "GET /wp-content/themes/twentytwentytwo/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:01 +0330] "GET /wp-admin/css/elementskit.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:06:59:02 +0330] "GET /js/1.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:04 +0330] "GET /wp-content/themes/twentytwentyfour/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:05 +0330] "GET /wp-includes/assets/min.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:07 +0330] "GET /wp-includes/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:08 +0330] "GET /backup/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:06:59:10 +0330] "GET /wp-content/uploads/uploads.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:06:59:11 +0330] "GET /wp-includes/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:13 +0330] "GET /wp-content/themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:59:14 +0330] "GET /wp-includes/block-patterns/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:16 +0330] "GET /worm0.PhP7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:18 +0330] "GET /wp-includes/load.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:18 +0330] "GET /wp-includes/ID3/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:59:20 +0330] "GET /wp-includes/class-wp-theme-float.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:59:22 +0330] "GET /images/c99.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:59:23 +0330] "GET /wp-content/plugins/core-plugin/waf_defender.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:25 +0330] "GET /wp-content/themes/twentytwentytwo/as.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:26 +0330] "GET /wp-includes/widgets/wp-style.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:28 +0330] "GET /setup-config.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:29 +0330] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:31 +0330] "GET /wp-content/uploads/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:33 +0330] "GET /img/prettyPhoto/dark_square/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:34 +0330] "GET /type.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:36 +0330] "GET /wp-includes/block-bindings/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:06:59:37 +0330] "GET /wp-includes/PHPMailer/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:06:59:38 +0330] "GET /as/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:59:40 +0330] "GET /wp-includes/theme-compat/db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:59:41 +0330] "GET /wp-admin/maint/flex.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:43 +0330] "GET /css/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:06:59:44 +0330] "GET /css/hekokstyle.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:06:59:46 +0330] "GET /wp-admin/user/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:47 +0330] "GET /files/shares/403ws.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:49 +0330] "GET /goat.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:06:59:50 +0330] "GET /images/fix.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:06:59:52 +0330] "GET /wp-content/themes/tflow/adminfus.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:53 +0330] "GET /files.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:59:55 +0330] "GET /wp-includes/assets/system.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:06:59:56 +0330] "GET /wp-includes/l10n/class-wp-translations-library.php%20 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:58 +0330] "GET /wp-includes/block-bindings/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:06:59:59 +0330] "GET /images/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:00:01 +0330] "GET /wp-content/plugins/linkpreview/av.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:03 +0330] "GET /wp-includes/customize/class-wp-customize-upload-control-cookie.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:04 +0330] "GET /wp-includes/ID3/simi.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:06 +0330] "GET /wp-includes/class-wp-taxonomy-sample.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:00:07 +0330] "GET /img/chat-search.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 208.84.101.66 - - [30/Nov/2025:07:00:06 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:09 +0330] "GET /wp-includes/css/dist/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:09 +0330] "GET /wp-includes/js/dist/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:10 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:00:10 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:11 +0330] "GET /wp-content/plugins/erinyani/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:13 +0330] "GET /wp-includes/l10n/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:13 +0330] "GET /wp-content/uploads/2023/11/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:07:00:14 +0330] "GET /wp-includes/sodium_compat/lib/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:00:14 +0330] "GET /wp-includes/blocks/file/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:15 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:16 +0330] "GET /wp-includes/block-bindings/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.81 - - [30/Nov/2025:07:00:16 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:00:17 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:00:17 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:19 +0330] "GET /wp-admin/css/colors/sunrise/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:00:19 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:20 +0330] "GET /wp-content/plugins/ioxi/ioxi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:00:21 +0330] "GET /wp-includes/id3/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:23 +0330] "GET /wp-includes/blocks/query/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:07:00:24 +0330] "GET /wp-includes/js/tinymce/langs/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:24 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:00:25 +0330] "GET /wp-includes/blocks/group/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:07:00:25 +0330] "GET /blog/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:27 +0330] "GET /wp-content/themes/twentytwentyfour/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:07:00:29 +0330] "GET /wp-includes/interactivity-api/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:29 +0330] "GET /wp-includes/wp-class.php/wp-content/themes/travelscape/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:31 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:00:31 +0330] "GET /wp-admin/js/dist/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:33 +0330] "GET /assets/css/dist/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:00:35 +0330] "GET /wp-includes/js/jquery/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:35 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:36 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:37 +0330] "GET /wp-content/plugins/wp-file-manager/admin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:00:38 +0330] "GET /wp-admin/js/widget/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:07:00:40 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:00:41 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:07:00:42 +0330] "GET /wp-content/themes/tflow/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:07:00:43 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:07:00:45 +0330] "GET /wordpress/wp-admin/includes HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:07:00:46 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:47 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:07:00:48 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:49 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:49 +0330] "GET /wp-includes/ID3 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:07:00:50 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 500 2 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:00:50 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:00:51 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:07:00:51 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:07:00:52 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:00:53 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:55 +0330] "GET /wp-content/uploads/ao_ccss/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:56 +0330] "GET /wp-content/uploads/2021/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:57 +0330] "GET /wp-content/plugins/elementor/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:00:58 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:07:00:59 +0330] "GET /upload/image/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:01 +0330] "GET /wordpress/wp-content/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:03 +0330] "GET /wordpress/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:07:01:04 +0330] "GET /blog/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:06 +0330] "GET /sites/default/files/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:01:07 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:09 +0330] "GET /admin/editor/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:01:10 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.5.82.81 - - [30/Nov/2025:07:01:12 +0330] "GET /admin/tmp/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:13 +0330] "GET /admin/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:15 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:17 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:18 +0330] "GET /administrator/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:07:01:20 +0330] "GET /ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:22 +0330] "GET /assets/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:01:23 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:24 +0330] "GET /components/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:01:26 +0330] "GET /home/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:01:27 +0330] "GET /include/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:07:01:29 +0330] "GET /modules/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:07:01:31 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:33 +0330] "GET /mt/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:34 +0330] "GET /site/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:01:36 +0330] "GET /tmps/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:07:01:37 +0330] "GET /wordpress/wp-admin/includes/wp-admin/js/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:01:39 +0330] "GET /wp-admin/css/colors/light/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:01:39 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:01:40 +0330] "GET /wp-admin/css/colors/modern/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:01:40 +0330] "GET /wp-admin/css/colors/ocean/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:41 +0330] "GET /wp-content/languages/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:01:42 +0330] "GET /wp-content/uploads/2022/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:07:01:42 +0330] "GET /wp-content/uploads/2023/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:43 +0330] "GET /wp-content/uploads/2024/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:43 +0330] "GET /wp-includes/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:45 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:46 +0330] "GET /wp-includes/ID3/wp-includes/IXR/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:01:47 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:07:01:48 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:48 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:49 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:51 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:01:51 +0330] "GET /wp-includes/js/plupload/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:01:52 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:52 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:53 +0330] "GET /cache-wordpress/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:07:01:55 +0330] "GET /wp-content/ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:56 +0330] "GET /wp-content/plugins/linkpreview/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:01:58 +0330] "GET /wp-content/plugins/aryabot/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:07:01:59 +0330] "GET /wp-content/plugins/BrutalShell/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:02:01 +0330] "GET /wp-content/plugins/cache-wordpress/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:03 +0330] "GET /wp-content/plugins/cakil/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:07:02:04 +0330] "GET /wp-content/plugins/cekidot/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:07:02:06 +0330] "GET /wp-content/plugins/db/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:08 +0330] "GET /wp-content/plugins/home/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:02:09 +0330] "GET /wp-content/plugins/limit/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:02:11 +0330] "GET /wp-content/plugins/owfsmac/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:02:13 +0330] "GET /wp-content/plugins/prenota/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.5.82.81 - - [30/Nov/2025:07:02:14 +0330] "GET /wp-content/plugins/random/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:07:02:16 +0330] "GET /wp-content/plugins/ubh/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:07:02:18 +0330] "GET /wp-content/plugins/Uwogh-Segs/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:02:19 +0330] "GET /wp-content/plugins/wp-diambar/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:21 +0330] "GET /wp-content/plugins/wp-freeform/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:07:02:23 +0330] "GET /wp-content/plugins/wp-hps/sh/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:07:02:25 +0330] "GET /wp-content/plugins/wpeazvp/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:26 +0330] "GET /wp-content/plugins/zaen/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:07:02:28 +0330] "GET /wp-content/uploads/revslider/templates/immersion-photography/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:02:29 +0330] "GET /patriotic/wp-includes/images/smilies/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:31 +0330] "GET /wp-includes/js/tinymce/plugins/fullscreen/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:32 +0330] "GET /wp-content/plugins/core-stab/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:33 +0330] "GET /wp-content/themes/alera/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:02:35 +0330] "GET /wp-content/themes/rishi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:36 +0330] "GET /wp-content/themes/sketch/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.5.82.81 - - [30/Nov/2025:07:02:38 +0330] "GET /wp-content/themes/thuoc-nam/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:39 +0330] "GET /wp-content/themes/twentyfive/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:41 +0330] "GET /wp-content/themes/wp-pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:42 +0330] "GET /wp-content/themes/pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:44 +0330] "GET /wp-content/themes/zakra/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:45 +0330] "GET /wp-content/uploads/simple-file-list/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.5.82.81 - - [30/Nov/2025:07:02:47 +0330] "GET /admin/upload/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:07:02:49 +0330] "GET /wp-admin/css/colors/blue/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:02:49 +0330] "GET /up/.well-known/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:02:51 +0330] "GET /wp-content/plugins/apikey/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:52 +0330] "GET /images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:53 +0330] "GET /css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:02:54 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:07:02:54 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:07:02:55 +0330] "GET /wp-includes/SimplePie/XML/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:02:56 +0330] "GET /wp-content/uploads/wpr-addons/forms/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:02:58 +0330] "GET /wp-content/plugins/WordPressCore/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:02:59 +0330] "GET /wordpress/wp-admin/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:03:02 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:02 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.5.82.81 - - [30/Nov/2025:07:03:03 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.5.82.81 - - [30/Nov/2025:07:03:03 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:04 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:03:04 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:03:05 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:06 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:03:06 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:03:07 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:03:07 +0330] "GET /wp-content/plugins/pwnd/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:07:03:09 +0330] "GET /about/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:03:11 +0330] "GET /plugins/jquery.filer/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:12 +0330] "GET /wp-content/plugins/dummyyummy/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:14 +0330] "GET /wp-content/themes/seotheme/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:15 +0330] "GET /wp-content/plugins/core/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:17 +0330] "GET /wp-content/plugins/revslider/includes/external/page/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:19 +0330] "GET /wp-content/plugins/Cache/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:20 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:21 +0330] "GET /wp-content/plugins/seoplugins/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:03:23 +0330] "GET /fonts/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:23 +0330] "GET /js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:24 +0330] "GET /routes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:26 +0330] "GET /uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:07:03:27 +0330] "GET /templates/beez3/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:29 +0330] "GET /wp-content/themes/digital-download/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:31 +0330] "GET /wp-content/plugins/wp-theme-editor/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.5.82.81 - - [30/Nov/2025:07:03:33 +0330] "GET /templates/atomic/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:34 +0330] "GET /wp-content/plugins/seoo/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:36 +0330] "GET /wp-includes/js/jcrop/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:36 +0330] "GET /wp-content/plugins/google-seo-rank/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:38 +0330] "GET /wp-content/plugins/erin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.5.82.81 - - [30/Nov/2025:07:03:40 +0330] "GET /wp-content/maintenance/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:40 +0330] "GET /wp-content/x/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:03:42 +0330] "GET /wp-content/plugins/seooyanz/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.5.82.81 - - [30/Nov/2025:07:03:43 +0330] "GET /wp-content/themes/sky-pro/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:03:45 +0330] "GET /wp-content/plugins/cp-pro/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:46 +0330] "GET /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:48 +0330] "GET /wp-content/uploads/typehub/custom/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.5.82.81 - - [30/Nov/2025:07:03:49 +0330] "GET /wp-content/plugins/rencontre/inc/photo_import/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.5.82.81 - - [30/Nov/2025:07:03:51 +0330] "GET /wp-content/plugins/backup-backup/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.5.82.81 - - [30/Nov/2025:07:03:53 +0330] "GET /wp-content/plugins/pwnd-1/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.5.82.81 - - [30/Nov/2025:07:03:54 +0330] "GET /.tmb/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.5.82.81 - - [30/Nov/2025:07:03:56 +0330] "GET /wp-content/plugins/fix/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:58 +0330] "GET /includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.5.82.81 - - [30/Nov/2025:07:03:59 +0330] "GET /themes/pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 31.214.174.196 - - [30/Nov/2025:07:04:21 +0330] "POST /wp-cron.php?doing_wp_cron=1764473660.8468248844146728515625 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 4.241.208.113 - - [30/Nov/2025:07:04:18 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:07:04:18 +0330] "GET / HTTP/1.1" 403 17364 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:07:04:18 +0330] "POST /wp-plain.php HTTP/1.1" 404 102572 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [30/Nov/2025:07:04:23 +0330] "GET /rgcjrlhu.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 193.142.146.65 - - [30/Nov/2025:07:17:41 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:22:39 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:22:46 +0330] "GET /filefuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:22:52 +0330] "GET /hplfuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:23:06 +0330] "GET /inputs.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:23:21 +0330] "GET /wp-content/termps.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 170.106.110.146 - - [30/Nov/2025:07:23:25 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 5.189.188.71 - - [30/Nov/2025:07:23:34 +0330] "GET /wp-content/postnews.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:23:54 +0330] "GET /classfuns.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:08 +0330] "GET /tempfuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:15 +0330] "GET /wp-content/connects.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:22 +0330] "GET /wp-content/siteheads.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:29 +0330] "GET /siteheads.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:36 +0330] "GET /ss.php?f_c=1 HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:25:03 +0330] "GET /wp-includes/Requests/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:25:09 +0330] "GET /wp.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 181.174.125.214 - - [30/Nov/2025:07:20:16 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 5.189.188.71 - - [30/Nov/2025:07:23:00 +0330] "GET /connects.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:23:13 +0330] "GET /termps.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:23:27 +0330] "GET /postnews.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:23:41 +0330] "GET /wp-content/hplfuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:23:47 +0330] "GET /userfuns.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:00 +0330] "GET /thoms.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:42 +0330] "GET /style.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:49 +0330] "GET /adminfuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:24:56 +0330] "GET /wp-content/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:25:16 +0330] "GET /cong.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:25:25 +0330] "GET /wp-content/upgrade.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:25:33 +0330] "GET /wp-content/content.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:25:39 +0330] "GET /content.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:25:53 +0330] "GET /wp-includes/Requests/chosen.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:07 +0330] "GET /.well-known/admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:13 +0330] "GET /wp-includes/dir/wp-login.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:20 +0330] "GET /wp-includes/fonts/wp-login.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:40 +0330] "GET /.well-known/acme-challenge/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:47 +0330] "GET /lv.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:01 +0330] "GET /lock.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:17 +0330] "GET /xmlrpc.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:44 +0330] "GET /wp-admin/install.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:01 +0330] "GET /wp-content/install.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:07 +0330] "GET /wp-admin/js/about.php7 HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:14 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:28 +0330] "GET /wp-includes/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:42 +0330] "GET /atomlib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:49 +0330] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:56 +0330] "GET /wp-content/plugins/seoplugins/mar.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:03 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:10 +0330] "GET /wp-includes/images/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:25:46 +0330] "GET /wp-admin/css/colors/blue/atomlib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:00 +0330] "GET /.well-known/acme-challenge/admin.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:27 +0330] "GET /about/function.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:33 +0330] "GET /.well-known/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:26:54 +0330] "GET /wp-admin/admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:07 +0330] "GET /.well-known/pki-validation/wp-login.php HTTP/1.1" 404 796 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:10 +0330] "GET /mah.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:24 +0330] "GET /wp-content/mah.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:31 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:37 +0330] "GET /wp-admin/images/admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:27:52 +0330] "GET /wp-includes/install.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:21 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:28:35 +0330] "GET /wp-includes/certificates/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:17 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:45 +0330] "GET /classwithtostring.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:24 +0330] "GET /wp-includes/pomo/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:31 +0330] "GET /wp-includes/rest-api/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:38 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:59 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:30:06 +0330] "GET /wp-includes/js/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:30:14 +0330] "GET /wp-admin/images/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:30:21 +0330] "GET /wp-admin/meta/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:30:28 +0330] "GET /function.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:30:35 +0330] "GET /wp-admin/network/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:30:42 +0330] "GET /wp-admin/user/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:30:49 +0330] "GET /wp-includes/assets/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:01 +0330] "GET /wp-includes/css/index.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:08 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:15 +0330] "GET /wp-includes/IXR/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:23 +0330] "GET /wp-includes/php-compat/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:45 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:29:53 +0330] "GET /wp-content/classwithtostring.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:30:54 +0330] "GET /wp-includes/blocks/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:30 +0330] "GET /wp-includes/PHPMailer/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:38 +0330] "GET /wp-includes/random_compat/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:52 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:32:13 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:32:33 +0330] "GET /wp-l0gin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:32:41 +0330] "GET /wp-content/plugins/plugins.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:32:54 +0330] "GET /wp-content/themes/themes.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:08 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:22 +0330] "GET /wp-content/themes/twentytwenty/functions.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:43 +0330] "GET /wp-login.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:34:04 +0330] "GET /link.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:34:11 +0330] "GET /wp-atom.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:34:25 +0330] "GET /sa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:34:32 +0330] "GET /ss.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:34:39 +0330] "GET /mar.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:34:46 +0330] "GET /wp-admin/admin-ajax.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:34:53 +0330] "GET /wp-admin/maint/plugins.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:07 +0330] "GET /wp-includes/certificates/plugins.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:31:59 +0330] "GET /wp-includes/Text/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:32:06 +0330] "GET /wp-admin/maint/wp-login.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:32:19 +0330] "GET /wp-admin/network/admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:32:26 +0330] "GET /404.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:32:47 +0330] "GET /wp-content/plugins/hello.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:01 +0330] "GET /wp-admin/maint/atomlib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:15 +0330] "GET /wp-content/themes/twentytwentythree/patterns/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:29 +0330] "GET /themes.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:36 +0330] "GET /index/function.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:49 +0330] "GET /edit.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:33:56 +0330] "GET /1.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:34:18 +0330] "GET /test.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:00 +0330] "GET /dropdown.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:28 +0330] "GET /wp-includes/sitemaps/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:36 +0330] "GET /wp-includes/sodium_compat/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:50 +0330] "GET /wp-admin/maint/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:36:04 +0330] "GET /admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:36:12 +0330] "GET /about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:36:27 +0330] "GET /wp-content/themes/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:36:33 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:36:40 +0330] "GET /wp-includes/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:07 +0330] "GET /wp-admin/css/about.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:15 +0330] "GET /wp-includes/js/radio.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:22 +0330] "GET /wp-includes/js/admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:36 +0330] "GET /wp-admin/meta/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:56 +0330] "GET /wp-includes/IXR/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:03 +0330] "GET /wp-includes/PHPMailer/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:09 +0330] "GET /wp-includes/SimplePie/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:23 +0330] "GET /wp-blog-header.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:30 +0330] "GET /wp-admin/network/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:36 +0330] "GET /wp-includes/admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:42 +0330] "GET /wp-content/plugins/elp.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:14 +0330] "GET /wp.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:21 +0330] "GET /wp-content/install.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:42 +0330] "GET /wp-includes/widgets/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:35:57 +0330] "GET /radio.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:36:19 +0330] "GET /wp-content/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:36:46 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:36:52 +0330] "GET /wp-admin/includes/admin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:01 +0330] "GET /wp-includes/images/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:09 +0330] "GET /wp-includes/js/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:30 +0330] "GET /wp-admin/images/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:43 +0330] "GET /wp-admin/network/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:37:50 +0330] "GET /wp-admin/user/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:16 +0330] "GET /wp-content/plugins/elp.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:04 +0330] "GET /wp-includes/PHPMailer/PHPMailer.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:52 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:40:06 +0330] "GET /wp-admin/network/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:40:26 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:40:33 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:40:40 +0330] "GET /wp-admin/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:40:46 +0330] "GET /wp-admin/css/colors/ectoplasm/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:48 +0330] "GET /wp-content/plugins/akismet/index.php HTTP/1.1" 403 787 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:51 +0330] "GET /wp-includes/ID3/getid3.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:38:58 +0330] "GET /wp-includes/PHPMailer/Exception.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:11 +0330] "GET /wp-includes/PHPMailer/SMTP.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:18 +0330] "GET /wp-includes/Requests/input.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:24 +0330] "GET /wp-includes/Requests/library/Requests.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:31 +0330] "GET /wp-includes/widgets/wp-login.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:38 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:46 +0330] "GET /wp-admin/images/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:39:59 +0330] "GET /wp-admin/meta/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:40:12 +0330] "GET /wp-admin/user/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:07:40:19 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:25:29 +0330] "GET /hplfuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:25:34 +0330] "GET /connects.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:25:41 +0330] "GET /inputs.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:25:54 +0330] "GET /wp-content/termps.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:13 +0330] "GET /wp-content/hplfuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:26 +0330] "GET /classfuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:32 +0330] "GET /thoms.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:38 +0330] "GET /tempfuns.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:51 +0330] "GET /wp-content/siteheads.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:09 +0330] "GET /style.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:35 +0330] "GET /wp.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:42 +0330] "GET /cong.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:49 +0330] "GET /wp-content/upgrade.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:56 +0330] "GET /wp-content/content.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:09 +0330] "GET /wp-admin/css/colors/blue/atomlib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:16 +0330] "GET /wp-includes/Requests/chosen.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:25:16 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:25:23 +0330] "GET /filefuns.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:25:47 +0330] "GET /termps.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:00 +0330] "GET /postnews.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:07 +0330] "GET /wp-content/postnews.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:20 +0330] "GET /userfuns.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:44 +0330] "GET /wp-content/connects.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:26:56 +0330] "GET /siteheads.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:02 +0330] "GET /ss.php?f_c=1 HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:15 +0330] "GET /adminfuns.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:21 +0330] "GET /wp-content/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:27:29 +0330] "GET /wp-includes/Requests/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:02 +0330] "GET /content.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:22 +0330] "GET /.well-known/acme-challenge/admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:49 +0330] "GET /about/function.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:55 +0330] "GET /.well-known/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:23 +0330] "GET /lock.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:29 +0330] "GET /.well-known/pki-validation/wp-login.php HTTP/1.1" 404 796 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:53 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:28 +0330] "GET /.well-known/admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:35 +0330] "GET /wp-includes/dir/wp-login.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:28:43 +0330] "GET /wp-includes/fonts/wp-login.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:02 +0330] "GET /.well-known/acme-challenge/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:09 +0330] "GET /lv.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:15 +0330] "GET /wp-admin/admin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:32 +0330] "GET /mah.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:39 +0330] "GET /xmlrpc.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:45 +0330] "GET /wp-content/mah.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:29:59 +0330] "GET /wp-admin/images/admin.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:06 +0330] "GET /wp-admin/install.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:12 +0330] "GET /wp-includes/install.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:18 +0330] "GET /wp-content/install.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:25 +0330] "GET /wp-admin/js/about.php7 HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:32 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:39 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:51 +0330] "GET /wp-includes/certificates/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:12 +0330] "GET /wp-content/plugins/seoplugins/mar.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:19 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:33 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:39 +0330] "GET /wp-includes/pomo/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:53 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:06 +0330] "GET /wp-content/classwithtostring.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:12 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:26 +0330] "GET /wp-admin/images/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:38 +0330] "GET /function.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:45 +0330] "GET /wp-admin/network/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:03 +0330] "GET /wp-includes/blocks/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:45 +0330] "GET /wp-includes/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:30:59 +0330] "GET /atomlib.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:05 +0330] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:26 +0330] "GET /wp-includes/images/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:46 +0330] "GET /wp-includes/rest-api/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:31:59 +0330] "GET /classwithtostring.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:20 +0330] "GET /wp-includes/js/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:31 +0330] "GET /wp-admin/meta/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:51 +0330] "GET /wp-admin/user/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:32:57 +0330] "GET /wp-includes/assets/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:16 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:23 +0330] "GET /wp-includes/IXR/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:36 +0330] "GET /wp-includes/PHPMailer/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:42 +0330] "GET /wp-includes/random_compat/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:55 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:10 +0330] "GET /wp-includes/css/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:29 +0330] "GET /wp-includes/php-compat/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:33:49 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.214.174.196 - - [30/Nov/2025:08:33:55 +0330] "GET /.well-known/pki-validation/moon.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:01 +0330] "GET /wp-includes/Text/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:06 +0330] "GET /wp-admin/maint/wp-login.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:12 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:17 +0330] "GET /wp-admin/network/admin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.214.174.196 - - [30/Nov/2025:08:34:21 +0330] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 5.189.188.71 - - [30/Nov/2025:08:34:30 +0330] "GET /wp-l0gin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:37 +0330] "GET /wp-content/plugins/plugins.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:43 +0330] "GET /wp-content/plugins/hello.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:35:02 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:35:10 +0330] "GET /wp-content/themes/twentytwentythree/patterns/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:35:23 +0330] "GET /themes.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:35:29 +0330] "GET /index/function.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:23 +0330] "GET /404.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:49 +0330] "GET /wp-content/themes/themes.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:34:56 +0330] "GET /wp-admin/maint/atomlib.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.214.174.196 - - [30/Nov/2025:08:35:09 +0330] "GET /.well-known/pki-validation/mariju.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 5.189.188.71 - - [30/Nov/2025:08:35:17 +0330] "GET /wp-content/themes/twentytwenty/functions.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:35:48 +0330] "GET /1.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:35:55 +0330] "GET /link.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:01 +0330] "GET /wp-atom.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:14 +0330] "GET /sa.php HTTP/1.1" 403 6890 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:21 +0330] "GET /ss.php HTTP/1.1" 403 6890 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:35 +0330] "GET /wp-admin/admin-ajax.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:54 +0330] "GET /wp-includes/certificates/plugins.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:00 +0330] "GET /wp.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:07 +0330] "GET /wp-content/install.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:13 +0330] "GET /wp-includes/sitemaps/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:19 +0330] "GET /wp-includes/sodium_compat/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:35:35 +0330] "GET /wp-login.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.214.174.196 - - [30/Nov/2025:08:35:37 +0330] "GET /.well-known/pki-validation/index.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 5.189.188.71 - - [30/Nov/2025:08:35:41 +0330] "GET /edit.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:08 +0330] "GET /test.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:28 +0330] "GET /mar.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:41 +0330] "GET /wp-admin/maint/plugins.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:36:47 +0330] "GET /dropdown.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:32 +0330] "GET /wp-admin/maint/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:44 +0330] "GET /admin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:51 +0330] "GET /about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:10 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:16 +0330] "GET /wp-includes/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:38 +0330] "GET /wp-admin/css/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:26 +0330] "GET /wp-includes/widgets/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:38 +0330] "GET /radio.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:37:57 +0330] "GET /wp-content/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:03 +0330] "GET /wp-content/themes/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:22 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:27 +0330] "GET /wp-admin/includes/admin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:33 +0330] "GET /wp-includes/images/about.php HTTP/1.1" 403 6890 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:44 +0330] "GET /wp-includes/js/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:50 +0330] "GET /wp-includes/js/radio.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:38:57 +0330] "GET /wp-includes/js/admin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:39:09 +0330] "GET /wp-admin/meta/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.214.174.196 - - [30/Nov/2025:08:41:01 +0330] "GET /.well-known/pki-validation/2index.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 31.214.174.196 - - [30/Nov/2025:08:44:16 +0330] "GET /.well-known/pki-validation/server.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 5.189.188.71 - - [30/Nov/2025:08:39:03 +0330] "GET /wp-admin/images/about.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.214.174.196 - - [30/Nov/2025:08:40:34 +0330] "GET /.well-known/pki-validation/1.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 31.214.174.196 - - [30/Nov/2025:08:40:37 +0330] "GET /.well-known/pki-validation/install.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 31.214.174.196 - - [30/Nov/2025:08:41:21 +0330] "GET /.well-known/pki-validation/class_api.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 185.2.4.78 - - [30/Nov/2025:08:41:31 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 31.214.174.196 - - [30/Nov/2025:08:44:52 +0330] "GET /.well-known/pki-validation/kur.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 31.214.174.196 - - [30/Nov/2025:08:45:01 +0330] "GET /.well-known/pki-validation/xmrlpc.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 31.214.174.196 - - [30/Nov/2025:08:46:46 +0330] "GET /.well-known/pki-validation/webdb.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.27.93.214 - - [30/Nov/2025:09:22:52 +0330] "GET /?utm_source=ig&utm_medium=social&utm_content=link_in_bio&fbclid=PAZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQPMTI0MDI0NTc0Mjg3NDE0AAGne5Vpc2GOnluBe8A3qvFBGQDCFwlpYFgV8FVA5Le1PslUDO8b6cd2VMX_6IQ_aem_jyytk6UTX24ye6tVXqBu_A HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/23B85 Instagram 407.0.0.31.80 (iPhone13,3; iOS 26_1; en_US; en; scale=3.00; 1170x2532; IABMV/1; 826175880) Safari/604.1" 5.113.185.107 - - [30/Nov/2025:10:05:19 +0330] "GET /wp-content/uploads/2020/12/logo2.png HTTP/1.1" 200 4490 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" 78.39.19.17 - - [30/Nov/2025:10:41:57 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.1 Mobile/15E148 Safari/604.1" 51.68.107.157 - - [30/Nov/2025:10:45:41 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; MJ12bot/v2.0.4; http://mj12bot.com/)" 193.28.182.59 - - [30/Nov/2025:10:47:17 +0330] "GET / HTTP/1.1" 301 20 "https://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68" 193.28.182.59 - - [30/Nov/2025:10:47:28 +0330] "GET /sevices/ HTTP/1.1" 301 20 "https://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68" 182.44.8.254 - - [30/Nov/2025:10:49:02 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 2.177.244.200 - - [30/Nov/2025:11:24:45 +0330] "GET /wp-content/uploads/2020/12/logo2.png HTTP/1.1" 200 4490 "https://optimyar.com/" "Mozilla/5.0 (Linux; Android 10; AQM-LX1; HMSCore 6.15.4.322) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.196 HuaweiBrowser/16.0.6.300 Mobile Safari/537.36" 106.75.17.115 - - [30/Nov/2025:12:02:12 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 7_1_1; Win64; x64) AppleWebKit/558.53 (KHTML, like Gecko) Chrome/61.0.1030 Safari/537.36" 43.130.40.120 - - [30/Nov/2025:12:34:03 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 82.208.32.34 - - [30/Nov/2025:13:21:13 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68" 43.165.69.68 - - [30/Nov/2025:13:24:51 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 44.195.201.244 - - [30/Nov/2025:13:40:45 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 66.249.66.11 - - [30/Nov/2025:14:21:43 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.74 - - [30/Nov/2025:14:21:47 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 77.237.245.107 - - [30/Nov/2025:14:34:59 +0330] "HEAD / HTTP/1.1" 301 0 "-" "python-requests/2.32.5" 185.2.5.31 - - [30/Nov/2025:14:44:42 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 81.88.52.75 - - [30/Nov/2025:15:57:37 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 145.220.91.19 - - [30/Nov/2025:15:56:02 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:122.0) Gecko/20100101 Firefox/122.0" 98.190.239.3 - - [30/Nov/2025:16:45:52 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 98.190.239.3 - - [30/Nov/2025:16:46:02 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 98.190.239.3 - - [30/Nov/2025:16:46:28 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 119.249.100.109 - - [30/Nov/2025:16:48:40 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 110.49.126.114 - - [30/Nov/2025:16:56:34 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 155.117.20.141 - - [30/Nov/2025:16:46:07 +0330] "GET /wp-json/dokan/v1/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 11) Chrome/123.0 Mobile" 98.190.239.3 - - [30/Nov/2025:16:46:10 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 81.88.52.239 - - [30/Nov/2025:17:06:25 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 46.101.123.64 - - [30/Nov/2025:17:24:03 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 14.215.163.132 - - [30/Nov/2025:17:27:36 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 72.13.62.26 - - [30/Nov/2025:17:47:19 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; ips-agent)" 72.13.62.26 - - [30/Nov/2025:17:47:23 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; ips-agent)" 72.13.62.26 - - [30/Nov/2025:17:47:38 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; ips-agent)" 45.154.98.45 - - [30/Nov/2025:17:51:46 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 162.62.213.165 - - [30/Nov/2025:18:11:37 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 103.52.212.8 - - [30/Nov/2025:18:13:46 +0330] "HEAD / HTTP/1.1" 301 0 "-" "python-requests/2.32.5" 104.236.100.191 - - [30/Nov/2025:19:05:42 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 162.62.231.139 - - [30/Nov/2025:19:10:50 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 165.227.98.14 - - [30/Nov/2025:19:19:06 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 66.249.66.165 - - [30/Nov/2025:19:32:40 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 5.210.28.100 - - [30/Nov/2025:19:36:55 +0330] "GET / HTTP/1.1" 301 20 "android-app://org.telegram.messenger/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Mobile Safari/537.36" 173.252.82.23 - - [30/Nov/2025:19:42:45 +0330] "GET / HTTP/1.1" 301 0 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 173.252.82.25 - - [30/Nov/2025:19:42:51 +0330] "GET /?wordfence_syncAttackData=1764519169.2223 HTTP/1.1" 301 0 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 66.249.66.165 - - [30/Nov/2025:19:32:37 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.199 - - [30/Nov/2025:19:32:40 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 31.13.115.9 - - [30/Nov/2025:19:42:58 +0330] "GET /?fbclid=IwZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMjU2MjgxMDQwNTU4AAEerpDi2O418ySlCT3Tw4tBHFi96HC37DaFjuqMgS44UNPh_tLrRiqpoedWLxI_aem__zHH2m1D8lci7RYbt0qscA HTTP/1.1" 301 20 "http://m.facebook.com" "Instagram 407.0.0.31.80 (iPhone13,3; iOS 26_1; en_US; en; scale=3.00; 1170x2532; 826175880) AppleWebKit/420+" 173.252.95.41 - - [30/Nov/2025:19:46:03 +0330] "GET /?fbclid=IwZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMjU2MjgxMDQwNTU4AAEeMGUZ7Vl4KGCnLo7-axLBx9L9eDaSQM2Wr3F5NTg2yAMkLVXQqDSc7cjXwFY_aem_uw5b48ufjxtIlpSQ8c3aDA HTTP/1.1" 301 20 "https://www.facebook.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" 81.88.52.75 - - [30/Nov/2025:19:53:46 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 62.60.130.210 - - [30/Nov/2025:19:58:12 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "https://twitter.com/" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36" 46.41.201.175 - - [30/Nov/2025:20:04:49 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:145.0) Gecko/20100101 Firefox/145.0" 77.90.185.10 - - [30/Nov/2025:20:25:25 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/119.0.1" 165.227.98.14 - - [30/Nov/2025:21:24:19 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 165.227.98.14 - - [30/Nov/2025:23:14:30 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 167.71.69.173 - - [30/Nov/2025:23:38:33 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:85.0) Gecko/20100101 Firefox/91.0" 5.189.188.71 - - [30/Nov/2025:23:50:32 +0330] "GET /postnews.php HTTP/1.1" 301 20 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 5.189.188.71 - - [30/Nov/2025:23:52:31 +0330] "GET /postnews.php HTTP/1.1" 301 20 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 5.189.188.71 - - [30/Nov/2025:23:52:59 +0330] "GET /ss.php?f_c=1 HTTP/1.1" 301 20 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 5.189.188.71 - - [30/Nov/2025:23:51:01 +0330] "GET /ss.php?f_c=1 HTTP/1.1" 301 20 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 43.159.140.236 - - [01/Dec/2025:00:09:01 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 2.189.80.20 - - [30/Nov/2025:23:58:50 +0330] "GET /?utm_source=ig&utm_medium=social&utm_content=link_in_bio&fbclid=PAZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQPMTI0MDI0NTc0Mjg3NDE0AAGn9o7z4OYQ3lXnKLQab48IlQBjVFtrGq5yCZP2-ZgRy-8GZFmAfKGnUow3fcg_aem_zcsS8amv-rsAVvGxoWXbZA HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_6_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/22G100 Instagram 405.1.0.27.75 (iPhone16,1; iOS 18_6_2; en_US; en; scale=3.00; 1179x2556; IABMV/1; 817093285) Safari/604.1" 43.135.172.89 - - [01/Dec/2025:01:00:18 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 185.27.132.26 - - [01/Dec/2025:02:03:51 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 35.153.182.212 - - [01/Dec/2025:02:10:39 +0330] "GET /sevices/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36" 75.119.143.158 - - [01/Dec/2025:02:26:11 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 185.181.244.141 - - [01/Dec/2025:03:35:22 +0330] "GET /hello-world/ HTTP/1.0" 301 0 "http://optimyar.com/hello-world/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 5.252.55.178 - - [01/Dec/2025:04:17:02 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.252.55.178 - - [01/Dec/2025:04:17:02 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.252.55.178 - - [01/Dec/2025:04:17:02 +0330] "GET / HTTP/1.1" 403 17362 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.252.55.178 - - [01/Dec/2025:04:17:03 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.252.55.178 - - [01/Dec/2025:04:17:02 +0330] "POST /wp-plain.php HTTP/1.1" 404 101828 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.252.55.178 - - [01/Dec/2025:04:17:07 +0330] "GET /jnxhfkkw.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 92.118.39.100 - - [01/Dec/2025:04:11:05 +0330] "GET /.env HTTP/1.1" 301 0 "-" "-" 5.252.55.178 - - [01/Dec/2025:04:17:02 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 45.80.158.89 - - [01/Dec/2025:04:49:47 +0330] "GET / HTTP/1.1" 403 17362 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.89 - - [01/Dec/2025:04:49:47 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 45.80.158.89 - - [01/Dec/2025:04:49:47 +0330] "POST /wp-plain.php HTTP/1.1" 404 101827 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.89 - - [01/Dec/2025:04:49:51 +0330] "GET /mprqheuz.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.89 - - [01/Dec/2025:04:49:47 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.89 - - [01/Dec/2025:04:49:47 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.89 - - [01/Dec/2025:04:49:47 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 66.249.66.161 - - [01/Dec/2025:05:06:37 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.2 - - [01/Dec/2025:05:06:33 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 20.6.32.251 - - [01/Dec/2025:05:07:49 +0330] "GET /.env HTTP/1.1" 301 20 "-" "python-requests/2.32.4" 77.90.185.240 - - [01/Dec/2025:05:20:11 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "https://www.reddit.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.5993.88 Safari/537.36" 66.249.66.3 - - [01/Dec/2025:05:23:14 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.44 - - [01/Dec/2025:05:23:20 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.2 - - [01/Dec/2025:05:23:22 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.84 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 182.44.2.148 - - [01/Dec/2025:06:13:52 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 43.134.141.244 - - [01/Dec/2025:06:14:46 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 125.27.93.31 - - [01/Dec/2025:06:26:10 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 18.237.33.191 - - [01/Dec/2025:06:32:55 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.10 Safari/605.1.1" 170.106.35.153 - - [01/Dec/2025:07:08:11 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 51.68.247.209 - - [01/Dec/2025:06:59:12 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 198.244.242.192 - - [01/Dec/2025:06:59:24 +0330] "GET /%D8%A7%D8%B1%D8%AA%D8%A8%D8%A7%D8%B7-%D8%A8%D8%A7-%D8%B5%D9%86%D8%B9%D8%AA/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 54.38.147.2 - - [01/Dec/2025:07:17:16 +0330] "GET /sevices/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 155.248.254.73 - - [01/Dec/2025:07:35:32 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 13.217.110.49 - - [01/Dec/2025:08:08:33 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36" 173.44.175.228 - - [01/Dec/2025:08:10:24 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:13:12 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.41.75.148 - - [01/Dec/2025:08:13:24 +0330] "GET /buy.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:13:30 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:13:30 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:13:35 +0330] "GET /file.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:13:40 +0330] "GET /flower.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:13:45 +0330] "GET /images/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:13:50 +0330] "GET /info.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:14:00 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:14:06 +0330] "GET /nc4.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:14:12 +0330] "GET /xleet.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:14:18 +0330] "GET /1.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:14:23 +0330] "GET /403.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:14:35 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:14:41 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 198.244.240.59 - - [01/Dec/2025:08:09:51 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 20.41.75.148 - - [01/Dec/2025:08:13:05 +0330] "GET /aa.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:13:18 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.41.75.148 - - [01/Dec/2025:08:14:29 +0330] "GET /about.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:14:53 +0330] "GET /alfa.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:15:06 +0330] "GET /as.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:15:19 +0330] "GET /asd.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:15:26 +0330] "GET /assets/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:15:39 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:15:53 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:15:59 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:16:20 +0330] "GET /ds.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:16:34 +0330] "GET /files/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:16:44 +0330] "GET /function.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:16:51 +0330] "GET /gelay.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:16:58 +0330] "GET /gfile.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:17:05 +0330] "GET /gg.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:14:47 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:14:59 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:15:12 +0330] "GET /asasx.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:15:33 +0330] "GET /assets/images/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:15:47 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:16:06 +0330] "GET /dex.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:16:13 +0330] "GET /doc.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:16:27 +0330] "GET /files/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:17:18 +0330] "GET /i.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:17:31 +0330] "GET /inc.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:17:51 +0330] "GET /ini.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:17:58 +0330] "GET /inputs.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:18:40 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:19:00 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:19:06 +0330] "GET /robots.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:19:34 +0330] "GET /upload/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:19:49 +0330] "GET /wp-admin.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:17:11 +0330] "GET /goods.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:17:25 +0330] "GET /images/images/about.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:17:39 +0330] "GET /index.bak.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:17:44 +0330] "GET /index/function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:18:11 +0330] "GET /item.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:18:19 +0330] "GET /manager.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:18:26 +0330] "GET /modules/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:18:33 +0330] "GET /moon.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:18:46 +0330] "GET /past.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:18:53 +0330] "GET /php/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:19:13 +0330] "GET /shop.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.41.75.148 - - [01/Dec/2025:08:19:20 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:19:27 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:19:41 +0330] "GET /vendor/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:19:56 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:20:29 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:20:29 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:20:29 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:20:09 +0330] "GET /wp-admin/includes/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:20:09 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:20:15 +0330] "GET /wp-content/uploads/admin.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:20:22 +0330] "GET /wp-good.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:20:36 +0330] "GET /adminfuns.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:20:44 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:20:50 +0330] "GET /cong.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 165.227.98.14 - - [01/Dec/2025:08:20:52 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:20:56 +0330] "GET /file2.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:03 +0330] "GET /wp-admin/css/colors/blue/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:21:22 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:21:27 +0330] "GET /wp-content/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:34 +0330] "GET /wp-cron.php HTTP/1.1" 200 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:21:34 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:35 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:35 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:35 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:40 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:41 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:21:41 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:41 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:21:54 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:54 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:21:54 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:21:54 +0330] "GET /wp-admin/css/colors/light/function.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:22:07 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:22:07 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:22:08 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:22:20 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:23:07 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:23:07 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:23:19 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:23:31 +0330] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:23:43 +0330] "GET /wp-blog-header.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:23:49 +0330] "GET /wp-comments.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:24:16 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:24:23 +0330] "GET /wp-content/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:24:58 +0330] "GET /wp-content/themes/ HTTP/1.1" 200 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:24:58 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:21:15 +0330] "GET /wp-content/index.php HTTP/1.1" 200 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:21:16 +0330] "GET /wp-content/plugins/yanierin/akcc.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:22:32 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:22:44 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:22:44 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:22:44 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:22:55 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 51.89.129.164 - - [01/Dec/2025:08:23:31 +0330] "GET /academic-co-working/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 20.41.75.148 - - [01/Dec/2025:08:23:56 +0330] "GET /wp-conflg.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:24:02 +0330] "GET /wp-content/ HTTP/1.1" 200 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:24:03 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:24:09 +0330] "GET /wp-content/Geforce.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:24:30 +0330] "GET /wp-content/plugins/ HTTP/1.1" 200 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:24:30 +0330] "GET /wp-content/plugins/HelloDollyV2/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:24:37 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:24:44 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:24:50 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:05 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 200 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:25:05 +0330] "GET /wp-content/themes/themes.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:32 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:25:32 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:25:32 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:25:45 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:45 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:51 +0330] "GET /wp-includes/SimplePie/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:04 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:08 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:09 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.41.75.148 - - [01/Dec/2025:08:26:09 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:26:09 +0330] "GET /wp-includes/Text/Diff/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:14 +0330] "GET /wp-includes/Text/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:21 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:21 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:12 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:12 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:12 +0330] "GET /wp-content/uploads/Geforce.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:19 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:25:19 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:25:20 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:25:25 +0330] "GET /wp-includes/IXR/test1.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:25:39 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:25:57 +0330] "GET /wp-includes/SimplePie/chosen.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:26:28 +0330] "GET /wp-includes/bk/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:26:38 +0330] "GET /wp-includes/block-bindings/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:38 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:26:38 +0330] "GET /wp-includes/blocks/shortcode/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:44 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.41.75.148 - - [01/Dec/2025:08:26:44 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:44 +0330] "GET /wp-includes/css/dist/alam.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:51 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:26:51 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:26:56 +0330] "GET /wp-content/cache/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:03 +0330] "GET /wp-content/w3tc/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:23 +0330] "GET /wp-content/wflogs/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:27:23 +0330] "GET /wp-content/updraft/ HTTP/1.1" 200 112 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:23 +0330] "GET /wp-content/ai1wm-backups/ HTTP/1.1" 200 26 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:24 +0330] "GET /wp-content/backups-dup-lite/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:27:44 +0330] "GET /wp-content/uploads/wc-logs/ HTTP/1.1" 200 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:27:44 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:45 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:45 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:27:52 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:27:52 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:52 +0330] "GET /wp-includes/images/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:56 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:10 +0330] "GET /wp-content/et-cache/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:17 +0330] "GET /wp-content/cache/supercache/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:27:31 +0330] "GET /wp-content/backup-db/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:27:38 +0330] "GET /wp-content/uploads/woocommerce_uploads/ HTTP/1.1" 200 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:27:38 +0330] "GET /wp-content/uploads/woocommerce/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:31 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:31 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:31 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:32 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:32 +0330] "GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:37 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:28:37 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:37 +0330] "GET /wp-includes/sodium_compat/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:28:42 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:28:42 +0330] "GET /wp-includes/style-engine/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.41.75.148 - - [01/Dec/2025:08:27:57 +0330] "GET /wp-includes/images/media/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:28:02 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:02 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:12 +0330] "GET /wp-includes/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:17 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:17 +0330] "GET /wp-includes/js/jcrop/jcrop.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:24 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:24 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:25 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:29:11 +0330] "GET /wp-update.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:29:25 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:29:25 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:29:26 +0330] "GET /.well-known/acme-challenge/xa.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:28:48 +0330] "GET /wp-includes/style-engine/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:28:54 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:28:55 +0330] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:29:02 +0330] "GET /wp-mail.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:29:05 +0330] "GET /wp-signin.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.41.75.148 - - [01/Dec/2025:08:29:18 +0330] "GET /wp.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.41.75.148 - - [01/Dec/2025:08:29:32 +0330] "GET /.well-known/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 111.227.78.3 - - [01/Dec/2025:09:17:42 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0" 111.227.78.3 - - [01/Dec/2025:09:18:40 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0" 198.244.242.100 - - [01/Dec/2025:09:35:50 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 143.198.106.230 - - [01/Dec/2025:09:36:04 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 4.241.208.113 - - [01/Dec/2025:09:52:33 +0330] "HEAD / HTTP/1.1" 301 0 "-" "python-requests/2.32.4" 4.241.208.113 - - [01/Dec/2025:09:52:36 +0330] "HEAD / HTTP/1.1" 301 0 "-" "python-requests/2.32.4" 43.166.244.66 - - [01/Dec/2025:12:07:31 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 91.224.92.127 - - [01/Dec/2025:12:23:49 +0330] "POST /wp-confiq.php HTTP/1.1" 404 15074 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (bot, like Gecko) Chrome/140.0.7339.210 Safari/537.36" 84.247.191.22 - - [01/Dec/2025:12:26:42 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 111.172.249.49 - - [01/Dec/2025:12:40:12 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 43.135.133.194 - - [01/Dec/2025:13:00:20 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 110.49.126.114 - - [01/Dec/2025:14:35:34 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 110.49.126.114 - - [01/Dec/2025:14:35:42 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "http://optimyar.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 216.73.216.15 - - [01/Dec/2025:14:53:24 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)" 152.42.181.252 - - [01/Dec/2025:15:05:55 +0330] "GET /sftp-config.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 152.42.181.252 - - [01/Dec/2025:15:06:01 +0330] "GET /.vscode/sftp.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 4.241.208.113 - - [01/Dec/2025:15:48:08 +0330] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 142.252.64.126 - - [01/Dec/2025:15:52:48 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/116.0" 87.121.84.125 - - [01/Dec/2025:16:14:18 +0330] "GET /assets/jquery-file-upload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 403 17364 "-" "ALittle Client" 194.38.22.4 - - [01/Dec/2025:16:26:52 +0330] "GET /assets/jquery-file-upload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 403 17364 "-" "ALittle Client" 78.153.140.222 - - [01/Dec/2025:16:43:12 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/600.8.9 (KHTML, like Gecko) Version/6.2.8 Safari/537.85.17" 78.153.140.222 - - [01/Dec/2025:16:43:13 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; InfoPath.2)" 78.153.140.222 - - [01/Dec/2025:16:43:14 +0330] "GET /sendgrid.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; U; Linux x86_64; it; rv:1.9) Gecko/2008061017 Firefox/3.0" 78.153.140.222 - - [01/Dec/2025:16:43:18 +0330] "GET /api/.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/538.1 (KHTML, like Gecko) janusvr Safari/538.1" 78.153.140.222 - - [01/Dec/2025:16:43:18 +0330] "GET /api/.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Maemo; Linux; U; Sailfish; Mobile; rv:38.0) Gecko/38.0 Firefox/38.0 SailfishBrowser/1.0" 78.153.140.222 - - [01/Dec/2025:16:43:20 +0330] "GET /phpinfo/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.57 Safari/537.17" 78.153.140.222 - - [01/Dec/2025:16:43:22 +0330] "GET /dev/.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.4 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.4" 78.153.140.222 - - [01/Dec/2025:16:43:24 +0330] "GET /app_dev.php/_profiler/phpinfo HTTP/1.1" 301 0 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0E; .NET4.0C)" 78.153.140.222 - - [01/Dec/2025:16:43:26 +0330] "GET /admin/.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Android 6.0.1;) AppleWebKit/1.1 Version/4.0 Mobile Safari/1.1" 78.153.140.222 - - [01/Dec/2025:16:43:33 +0330] "GET /secrets.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fa; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7" 78.153.140.222 - - [01/Dec/2025:16:43:35 +0330] "GET /.env.example HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.1.2 Safari/603.3.8" 78.153.140.222 - - [01/Dec/2025:16:43:38 +0330] "GET /.env.bak HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; U; Linux i686; sk; rv:1.9.0.5) Gecko/2008121621 Ubuntu/8.04 (hardy) Firefox/3.0.5" 78.153.140.222 - - [01/Dec/2025:16:43:45 +0330] "GET /core/.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; ja-jp) AppleWebKit/418.9.1 (KHTML, like Gecko) Safari/419.3" 78.153.140.222 - - [01/Dec/2025:16:43:10 +0330] "GET /.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_5) AppleWebKit/600.7.12 (KHTML, like Gecko) Version/6.2.7 Safari/537.85.16" 78.153.140.222 - - [01/Dec/2025:16:43:10 +0330] "GET /.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux; Android 6.0.1; SAMSUNG SM-G550T1 Build/MMB29K) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/6.4 Chrome/56.0.2924.87 Mobile Safari/537.36" 78.153.140.222 - - [01/Dec/2025:16:43:14 +0330] "GET /sendgrid.env HTTP/1.1" 301 0 "-" "Opera/9.20 (Windows NT 5.1; U; nb)" 78.153.140.222 - - [01/Dec/2025:16:43:16 +0330] "GET /twilio.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_7; da-dk) AppleWebKit/533.21.1 (KHTML, like Gecko) Version/5.0.5 Safari/533.21.1" 78.153.140.222 - - [01/Dec/2025:16:43:17 +0330] "GET /twilio.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 78.153.140.222 - - [01/Dec/2025:16:43:28 +0330] "GET /laravel/.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux; U; Android 2.2; pt-br; GT-P1000L Build/FROYO) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1" 78.153.140.222 - - [01/Dec/2025:16:43:30 +0330] "GET /.config.yaml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux; U; Android 2.3.3; en-us; LG-P999 Build/GRI40) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1 MMS/LG-Android-MMS-V1.0/1.2" 78.153.140.222 - - [01/Dec/2025:16:43:31 +0330] "GET /backend/.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_4; en-gb) AppleWebKit/528.4+ (KHTML, like Gecko) Version/4.0dp1 Safari/526.11.2" 78.153.140.222 - - [01/Dec/2025:16:43:37 +0330] "GET /web/.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.87 Safari/537.36" 78.153.140.222 - - [01/Dec/2025:16:43:40 +0330] "GET /staging/.env HTTP/1.1" 301 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" 78.153.140.222 - - [01/Dec/2025:16:43:43 +0330] "GET /debug/default/view?panel=config HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.70 Safari/537.36" 78.153.140.222 - - [01/Dec/2025:16:43:46 +0330] "GET /phpinfo.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML like Gecko) Chrome/37.0.2062.120 Safari/537.36" 78.153.140.222 - - [01/Dec/2025:16:43:49 +0330] "GET /info/ HTTP/1.1" 301 0 "-" "Opera/9.80 (Windows NT 6.2; Win64; x64) Presto/2.12.388 Version/12.11" 78.153.140.222 - - [01/Dec/2025:16:43:51 +0330] "GET /images/.env HTTP/1.1" 301 0 "-" "More Firefox 2.0.0.5 user agents strings -->>" 43.167.236.228 - - [01/Dec/2025:17:42:08 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 138.199.29.228 - - [01/Dec/2025:18:13:39 +0330] "GET /manager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:13:40 +0330] "GET /bless.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:41 +0330] "GET /O-Simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.228 - - [01/Dec/2025:18:13:42 +0330] "GET /lock360.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.228 - - [01/Dec/2025:18:13:43 +0330] "GET /zwso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:44 +0330] "GET /chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:45 +0330] "GET /about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 138.199.29.228 - - [01/Dec/2025:18:13:46 +0330] "GET /admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 138.199.29.228 - - [01/Dec/2025:18:13:47 +0330] "GET /.well-known/login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 138.199.29.228 - - [01/Dec/2025:18:13:49 +0330] "GET /mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:50 +0330] "GET /.wp/wso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:13:51 +0330] "GET /core.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:52 +0330] "GET /robots.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:53 +0330] "GET /inputs.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:54 +0330] "GET /mini.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:56 +0330] "GET /goods.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:13:57 +0330] "GET /file5.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:13:58 +0330] "GET /ahax.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:13:59 +0330] "GET /f35.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:00 +0330] "GET /simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:01 +0330] "GET /update/f35.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.228 - - [01/Dec/2025:18:14:02 +0330] "GET /wp-content/hello.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:03 +0330] "GET /wp-admin/maint/bootstrap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:14:04 +0330] "GET /themes/zMousse/otuz1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:05 +0330] "GET /wp-content/edit-wolf.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:14:06 +0330] "GET /wp-content/plugins/ubh/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:07 +0330] "GET /wp-admin/images/bootstrap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:08 +0330] "GET /images/upload.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:09 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.228 - - [01/Dec/2025:18:14:10 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 138.199.29.228 - - [01/Dec/2025:18:14:11 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:12 +0330] "GET /admin/uploads/bn_1_1754420677.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:14:13 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:14 +0330] "GET /wp-content/plugins/pwnd/pwnd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:15 +0330] "GET /wp-content/plugins/pwnd-1/pwnd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.228 - - [01/Dec/2025:18:14:16 +0330] "GET /wp-admin/css/colors/midnight/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 138.199.29.228 - - [01/Dec/2025:18:14:17 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/kill.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 138.199.29.228 - - [01/Dec/2025:18:14:18 +0330] "GET /wp-includes/style-engine/worksec.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:20 +0330] "GET /wp-admin/images/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:14:21 +0330] "GET /wp-content/plugins/core-plugin/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 138.199.29.228 - - [01/Dec/2025:18:14:22 +0330] "GET /wp-content/plugins/envato-css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:14:23 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:14:24 +0330] "GET /uploads/94056-upload.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:25 +0330] "GET /index/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:26 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.228 - - [01/Dec/2025:18:14:27 +0330] "GET /js/bas.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:28 +0330] "GET /.well-known/pki-validation/moon.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:14:28 +0330] "GET /file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:14:30 +0330] "GET /wp-includes/js/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.228 - - [01/Dec/2025:18:14:31 +0330] "GET /wp-content/upgrade/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:32 +0330] "GET /buy.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:33 +0330] "GET /wp-content/languages/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:34 +0330] "GET /wp-content/themes/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:35 +0330] "GET /wp-content/plugins/elementor/wp-wjvngrh.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 138.199.29.228 - - [01/Dec/2025:18:14:36 +0330] "GET /wp-includes/IXR/fix.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 138.199.29.228 - - [01/Dec/2025:18:14:37 +0330] "GET /wp-includes/widgets/dyqvcfqv.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:38 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:39 +0330] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:40 +0330] "GET /wp-includes/js/crop/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:41 +0330] "GET /wp-includes/PHPMailer/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.228 - - [01/Dec/2025:18:14:42 +0330] "GET /wp-includes/PHPMailer/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:43 +0330] "GET /wp-includes/widgets/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:44 +0330] "GET /files/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:45 +0330] "GET /wp-includes/PHPMailer/options.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:14:46 +0330] "GET /inc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:47 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:47 +0330] "GET /filemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:49 +0330] "GET /cgi-bin/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:14:50 +0330] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:14:50 +0330] "GET /wp-includes/IXR/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.228 - - [01/Dec/2025:18:14:51 +0330] "GET /wp-admin/js/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:14:52 +0330] "GET /wp-includes/js/jquery/jquery.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 138.199.29.228 - - [01/Dec/2025:18:14:53 +0330] "GET /function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 138.199.29.228 - - [01/Dec/2025:18:14:54 +0330] "GET /wp-includes/block-supports/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.228 - - [01/Dec/2025:18:14:55 +0330] "GET /wp-signup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 138.199.29.228 - - [01/Dec/2025:18:14:56 +0330] "GET /wp-admin/network/network.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:14:57 +0330] "GET /admin/upload/css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.228 - - [01/Dec/2025:18:14:58 +0330] "GET /wp-blog.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.228 - - [01/Dec/2025:18:14:59 +0330] "GET /wp-admin/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 138.199.29.228 - - [01/Dec/2025:18:15:00 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:02 +0330] "GET /wp-includes/blocks/table/int/tmpl/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 138.199.29.228 - - [01/Dec/2025:18:15:03 +0330] "GET /wp-l0gin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 138.199.29.228 - - [01/Dec/2025:18:15:04 +0330] "GET /wp-includes/js/jquery/suggest.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:05 +0330] "GET /new.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:06 +0330] "GET /wp-content/plugins/pwnd-1/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:07 +0330] "GET /wp-includes/defaults.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:09 +0330] "GET /images/DJP9.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:10 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:11 +0330] "GET /wp-admin/shell20211028.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:12 +0330] "GET /natural.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 138.199.29.228 - - [01/Dec/2025:18:15:13 +0330] "GET /item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:14 +0330] "GET /function/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:15 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:16 +0330] "GET /wp-admin/images/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:17 +0330] "GET /wp-includes/theme-compat/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:18 +0330] "GET /about/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:19 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:20 +0330] "GET /wp-includes/ID3/about.php/wp-content/x/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:15:21 +0330] "GET /wp-includes/ID3/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.228 - - [01/Dec/2025:18:15:22 +0330] "GET /wp-content/languages/404.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:15:23 +0330] "GET /update/403.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.228 - - [01/Dec/2025:18:15:24 +0330] "GET /default.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:26 +0330] "GET /wp-includes/assets/info.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:27 +0330] "GET /wp-includes/class.api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:15:28 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:15:29 +0330] "GET /wp-admin/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:30 +0330] "GET /autoload_classmap/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:15:31 +0330] "GET /dropdown.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:15:32 +0330] "GET /images/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:15:33 +0330] "GET /db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:15:34 +0330] "GET /.well-known/pki-validation/mariju.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.228 - - [01/Dec/2025:18:15:34 +0330] "GET /mah/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:35 +0330] "GET /wp-content/plugins/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:15:36 +0330] "GET /wp-includes/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:37 +0330] "GET /wp-content/themes/tflow/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:38 +0330] "GET /wp-admin/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:39 +0330] "GET /templates/beez3/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:15:40 +0330] "GET /wp-admin/js/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:15:41 +0330] "GET /install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:43 +0330] "GET /wp-admin/css/colors/blue/rk2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:44 +0330] "GET /images/class-config.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:45 +0330] "GET /components/com_jea/views/form/tmpl/size.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:46 +0330] "GET /templates/beez/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:47 +0330] "GET /bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:48 +0330] "GET /class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:15:50 +0330] "GET /wp-admin/css/colors/light/profile.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:15:51 +0330] "GET /wp-content/product.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:52 +0330] "GET /wp-content/uploads/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:15:53 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ask.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:15:54 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:55 +0330] "GET /css/css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:15:56 +0330] "GET /init.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:15:57 +0330] "GET /wp-admin/user/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.228 - - [01/Dec/2025:18:15:58 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:15:59 +0330] "GET /wp-includes/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 138.199.29.228 - - [01/Dec/2025:18:16:00 +0330] "GET /assets/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:01 +0330] "GET /.well-known/pki-validation/index.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 138.199.29.228 - - [01/Dec/2025:18:16:02 +0330] "GET /wp-content/uploads/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:03 +0330] "GET /css/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:04 +0330] "GET /adminfuns.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:06 +0330] "GET /wp-admin/css/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.228 - - [01/Dec/2025:18:16:07 +0330] "GET /wp_wlx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:08 +0330] "GET /wp-admin/js/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:09 +0330] "GET /wp-includes/assets/husky301.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:10 +0330] "GET /wp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:12 +0330] "GET /wp-admin/css/colors/blue/wp-trackback.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:13 +0330] "GET /wp-content/themes/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.228 - - [01/Dec/2025:18:16:14 +0330] "GET /wp-header.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:15 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:16:16 +0330] "GET /Marvins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:18 +0330] "GET /wp-content/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:19 +0330] "GET /wp-class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:20 +0330] "GET /wp-includes/images/smilies/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:21 +0330] "GET /xx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:22 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:16:23 +0330] "GET /wp-includes/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:16:24 +0330] "GET /wp-content/blue.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:16:26 +0330] "GET /content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:16:27 +0330] "GET /wp-content/uploads/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:28 +0330] "GET /wp-admin/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:16:30 +0330] "GET /wp-includes/rest-api/endpoints/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:16:31 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:32 +0330] "GET /wp-content/plugins/wp-theme-editor/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:16:33 +0330] "GET /wp-content/plugins/up/main.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:34 +0330] "GET /fonts/fontawesome-webfont.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 138.199.29.228 - - [01/Dec/2025:18:16:35 +0330] "GET /wp-admin/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:36 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:37 +0330] "GET /wp-admin/css/colors/blue/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:16:38 +0330] "GET /images/images/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:40 +0330] "GET /images/class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:16:41 +0330] "GET /wp-content/plugins/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.228 - - [01/Dec/2025:18:16:42 +0330] "GET /web.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:43 +0330] "GET /wp-admin/css/colors/ocean/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:44 +0330] "GET /images/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:45 +0330] "GET /wp-content/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:47 +0330] "GET /.well-known/gecko-litespeed.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:48 +0330] "GET /wp-admin/css/colors/midnight/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:16:49 +0330] "GET /wp-trackback.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:16:50 +0330] "GET /wp-includes/style-engine/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:16:52 +0330] "GET /radio.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:53 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.228 - - [01/Dec/2025:18:16:54 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:55 +0330] "GET /wp-admin/css/colors/midnight/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.228 - - [01/Dec/2025:18:16:56 +0330] "GET /wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.228 - - [01/Dec/2025:18:16:57 +0330] "GET /wp-setup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:16:59 +0330] "GET /ms-themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.228 - - [01/Dec/2025:18:17:00 +0330] "GET /wp-includes/assets/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 138.199.29.228 - - [01/Dec/2025:18:17:01 +0330] "GET /style.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:17:02 +0330] "GET /wp-includes/infi.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.228 - - [01/Dec/2025:18:17:04 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.228 - - [01/Dec/2025:18:17:05 +0330] "GET /x.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 138.199.29.228 - - [01/Dec/2025:18:17:06 +0330] "GET /wp-includes/IXR/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:17:21 +0330] "GET /wp-includes/css/dist/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:21 +0330] "GET /wp-includes/js/dist/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:21 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:21 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.211 - - [01/Dec/2025:18:17:21 +0330] "GET /wp-content/plugins/erinyani/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.211 - - [01/Dec/2025:18:17:22 +0330] "GET /wp-includes/l10n/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.211 - - [01/Dec/2025:18:17:23 +0330] "GET /wp-content/uploads/2023/11/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.211 - - [01/Dec/2025:18:17:23 +0330] "GET /wp-includes/sodium_compat/lib/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:17:23 +0330] "GET /wp-includes/blocks/file/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:23 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:23 +0330] "GET /wp-includes/block-bindings/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:23 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:23 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:23 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:25 +0330] "GET /wp-admin/css/colors/sunrise/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:25 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.211 - - [01/Dec/2025:18:17:25 +0330] "GET /wp-content/plugins/ioxi/ioxi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:26 +0330] "GET /wp-includes/id3/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:27 +0330] "GET /wp-includes/blocks/query/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:27 +0330] "GET /wp-includes/js/tinymce/langs/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:27 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:27 +0330] "GET /wp-includes/blocks/group/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:27 +0330] "GET /blog/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:28 +0330] "GET /wp-content/themes/twentytwentyfour/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 138.199.29.211 - - [01/Dec/2025:18:17:29 +0330] "GET /wp-includes/interactivity-api/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:17:30 +0330] "GET /wp-includes/wp-class.php/wp-content/themes/travelscape/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 138.199.29.211 - - [01/Dec/2025:18:17:31 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:31 +0330] "GET /wp-admin/js/dist/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:32 +0330] "GET /assets/css/dist/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:33 +0330] "GET /wp-includes/js/jquery/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:33 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:34 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:34 +0330] "GET /wp-content/plugins/wp-file-manager/admin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:35 +0330] "GET /wp-admin/js/widget/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 138.199.29.211 - - [01/Dec/2025:18:17:36 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:17:37 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:37 +0330] "GET /wp-content/themes/tflow/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 138.199.29.211 - - [01/Dec/2025:18:17:38 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.211 - - [01/Dec/2025:18:17:39 +0330] "GET /wordpress/wp-admin/includes HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:41 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:41 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.211 - - [01/Dec/2025:18:17:42 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:42 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:42 +0330] "GET /wp-includes/ID3 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:42 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 500 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.211 - - [01/Dec/2025:18:17:43 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:43 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:43 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:43 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:44 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:45 +0330] "GET /wp-content/uploads/ao_ccss/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:47 +0330] "GET /wp-content/uploads/2021/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:47 +0330] "GET /wp-content/plugins/elementor/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:47 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:48 +0330] "GET /upload/image/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:17:49 +0330] "GET /wordpress/wp-content/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:50 +0330] "GET /wordpress/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:17:51 +0330] "GET /blog/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:53 +0330] "GET /sites/default/files/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 138.199.29.211 - - [01/Dec/2025:18:17:54 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:55 +0330] "GET /admin/editor/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:17:56 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.211 - - [01/Dec/2025:18:17:57 +0330] "GET /admin/tmp/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:17:58 +0330] "GET /admin/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:17:59 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.211 - - [01/Dec/2025:18:18:00 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 138.199.29.211 - - [01/Dec/2025:18:18:01 +0330] "GET /administrator/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:18:03 +0330] "GET /ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:04 +0330] "GET /assets/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:05 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:18:05 +0330] "GET /components/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 138.199.29.211 - - [01/Dec/2025:18:18:06 +0330] "GET /home/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:18:07 +0330] "GET /include/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:08 +0330] "GET /modules/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:10 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:18:11 +0330] "GET /mt/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:18:12 +0330] "GET /site/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:13 +0330] "GET /tmps/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:18:14 +0330] "GET /wordpress/wp-admin/includes/wp-admin/js/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:15 +0330] "GET /wp-admin/css/colors/light/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:15 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:18:15 +0330] "GET /wp-admin/css/colors/modern/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:18:15 +0330] "GET /wp-admin/css/colors/ocean/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:16 +0330] "GET /wp-content/languages/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.211 - - [01/Dec/2025:18:18:16 +0330] "GET /wp-content/uploads/2022/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:16 +0330] "GET /wp-content/uploads/2023/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 138.199.29.211 - - [01/Dec/2025:18:18:16 +0330] "GET /wp-content/uploads/2024/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:18:16 +0330] "GET /wp-includes/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:17 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:18:17 +0330] "GET /wp-includes/ID3/wp-includes/IXR/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:18 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 138.199.29.211 - - [01/Dec/2025:18:18:18 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:18:18 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:18:19 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:20 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:20 +0330] "GET /wp-includes/js/plupload/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 138.199.29.211 - - [01/Dec/2025:18:18:20 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:20 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:20 +0330] "GET /cache-wordpress/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.211 - - [01/Dec/2025:18:18:22 +0330] "GET /wp-content/ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:23 +0330] "GET /wp-content/plugins/linkpreview/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:18:24 +0330] "GET /wp-content/plugins/aryabot/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:25 +0330] "GET /wp-content/plugins/BrutalShell/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:26 +0330] "GET /wp-content/plugins/cache-wordpress/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:27 +0330] "GET /wp-content/plugins/cakil/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:28 +0330] "GET /wp-content/plugins/cekidot/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:29 +0330] "GET /wp-content/plugins/db/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:31 +0330] "GET /wp-content/plugins/home/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:32 +0330] "GET /wp-content/plugins/limit/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:18:33 +0330] "GET /wp-content/plugins/owfsmac/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:18:34 +0330] "GET /wp-content/plugins/prenota/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:35 +0330] "GET /wp-content/plugins/random/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:36 +0330] "GET /wp-content/plugins/ubh/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:18:37 +0330] "GET /wp-content/plugins/Uwogh-Segs/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:18:38 +0330] "GET /wp-content/plugins/wp-diambar/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:18:39 +0330] "GET /wp-content/plugins/wp-freeform/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:18:40 +0330] "GET /wp-content/plugins/wp-hps/sh/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:42 +0330] "GET /wp-content/plugins/wpeazvp/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:43 +0330] "GET /wp-content/plugins/zaen/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:44 +0330] "GET /wp-content/uploads/revslider/templates/immersion-photography/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:45 +0330] "GET /patriotic/wp-includes/images/smilies/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:46 +0330] "GET /wp-includes/js/tinymce/plugins/fullscreen/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:47 +0330] "GET /wp-content/plugins/core-stab/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:48 +0330] "GET /wp-content/themes/alera/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.211 - - [01/Dec/2025:18:18:49 +0330] "GET /wp-content/themes/rishi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:50 +0330] "GET /wp-content/themes/sketch/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 138.199.29.211 - - [01/Dec/2025:18:18:51 +0330] "GET /wp-content/themes/thuoc-nam/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:18:52 +0330] "GET /wp-content/themes/twentyfive/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:18:53 +0330] "GET /wp-content/themes/wp-pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:54 +0330] "GET /wp-content/themes/pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:18:55 +0330] "GET /wp-content/themes/zakra/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:18:56 +0330] "GET /wp-content/uploads/simple-file-list/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:18:58 +0330] "GET /admin/upload/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:18:59 +0330] "GET /wp-admin/css/colors/blue/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:18:59 +0330] "GET /up/.well-known/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:00 +0330] "GET /wp-content/plugins/apikey/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:01 +0330] "GET /images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:19:02 +0330] "GET /css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:19:02 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:19:02 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:02 +0330] "GET /wp-includes/SimplePie/XML/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:03 +0330] "GET /wp-content/uploads/wpr-addons/forms/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:19:04 +0330] "GET /wp-content/plugins/WordPressCore/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:05 +0330] "GET /wordpress/wp-admin/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:06 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 138.199.29.211 - - [01/Dec/2025:18:19:06 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 138.199.29.211 - - [01/Dec/2025:18:19:06 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 138.199.29.211 - - [01/Dec/2025:18:19:06 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:19:06 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 138.199.29.211 - - [01/Dec/2025:18:19:07 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:07 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.211 - - [01/Dec/2025:18:19:07 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:07 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:19:07 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:19:07 +0330] "GET /wp-content/plugins/pwnd/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:19:08 +0330] "GET /about/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.211 - - [01/Dec/2025:18:19:09 +0330] "GET /plugins/jquery.filer/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:10 +0330] "GET /wp-content/plugins/dummyyummy/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 138.199.29.211 - - [01/Dec/2025:18:19:11 +0330] "GET /wp-content/themes/seotheme/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:12 +0330] "GET /wp-content/plugins/core/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:13 +0330] "GET /wp-content/plugins/revslider/includes/external/page/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:14 +0330] "GET /wp-content/plugins/Cache/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:19:15 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 138.199.29.211 - - [01/Dec/2025:18:19:16 +0330] "GET /wp-content/plugins/seoplugins/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:19:17 +0330] "GET /fonts/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 138.199.29.211 - - [01/Dec/2025:18:19:17 +0330] "GET /js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:19:17 +0330] "GET /routes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:19:18 +0330] "GET /uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:19 +0330] "GET /templates/beez3/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 138.199.29.211 - - [01/Dec/2025:18:19:20 +0330] "GET /wp-content/themes/digital-download/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 138.199.29.211 - - [01/Dec/2025:18:19:21 +0330] "GET /wp-content/plugins/wp-theme-editor/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 138.199.29.211 - - [01/Dec/2025:18:19:22 +0330] "GET /templates/atomic/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:23 +0330] "GET /wp-content/plugins/seoo/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:24 +0330] "GET /wp-includes/js/jcrop/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:19:24 +0330] "GET /wp-content/plugins/google-seo-rank/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:25 +0330] "GET /wp-content/plugins/erin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.211 - - [01/Dec/2025:18:19:26 +0330] "GET /wp-content/maintenance/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:26 +0330] "GET /wp-content/x/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 138.199.29.211 - - [01/Dec/2025:18:19:27 +0330] "GET /wp-content/plugins/seooyanz/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 138.199.29.211 - - [01/Dec/2025:18:19:28 +0330] "GET /wp-content/themes/sky-pro/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 138.199.29.211 - - [01/Dec/2025:18:19:29 +0330] "GET /wp-content/plugins/cp-pro/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 138.199.29.211 - - [01/Dec/2025:18:19:30 +0330] "GET /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:31 +0330] "GET /wp-content/uploads/typehub/custom/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:19:32 +0330] "GET /wp-content/plugins/rencontre/inc/photo_import/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:33 +0330] "GET /wp-content/plugins/backup-backup/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:34 +0330] "GET /wp-content/plugins/pwnd-1/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 138.199.29.211 - - [01/Dec/2025:18:19:35 +0330] "GET /.tmb/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 138.199.29.211 - - [01/Dec/2025:18:19:36 +0330] "GET /wp-content/plugins/fix/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:37 +0330] "GET /includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 138.199.29.211 - - [01/Dec/2025:18:19:39 +0330] "GET /themes/pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 4.241.208.113 - - [01/Dec/2025:18:37:11 +0330] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 43.157.180.116 - - [01/Dec/2025:18:42:17 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:52:46 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:52:46 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:52:46 +0330] "GET /.well-known/acme-challenge/xa.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:52:53 +0330] "GET /.well-known/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:52:57 +0330] "GET /1.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:53:03 +0330] "GET /403.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:53:09 +0330] "GET /aa.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:53:14 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:53:27 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:53:46 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:54:12 +0330] "GET /asasx.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:54:18 +0330] "GET /asd.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:54:31 +0330] "GET /assets/images/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:54:45 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:18:54:52 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:54:52 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:54:58 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:53:20 +0330] "GET /about.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:53:33 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:53:39 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:53:52 +0330] "GET /alfa.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:53:58 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:54:05 +0330] "GET /as.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:54:25 +0330] "GET /assets/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:18:54:38 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:55:24 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:55:45 +0330] "GET /files/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:56:03 +0330] "GET /function.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:56:17 +0330] "GET /gfile.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:18:56:24 +0330] "GET /gg.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:56:51 +0330] "GET /images/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:56:57 +0330] "GET /inc.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:57:24 +0330] "GET /ini.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:57:30 +0330] "GET /inputs.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:55:05 +0330] "GET /dex.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:55:11 +0330] "GET /doc.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:55:18 +0330] "GET /ds.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:55:30 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:55:37 +0330] "GET /files/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:56:10 +0330] "GET /gelay.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:56:30 +0330] "GET /goods.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:56:37 +0330] "GET /i.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:56:44 +0330] "GET /images/images/about.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:57:03 +0330] "GET /index.bak.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:57:10 +0330] "GET /index/function.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:57:17 +0330] "GET /info.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:57:50 +0330] "GET /manager.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:58:04 +0330] "GET /moon.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:58:10 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:58:17 +0330] "GET /past.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:58:56 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:57:37 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:57:43 +0330] "GET /item.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:57:56 +0330] "GET /modules/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:58:23 +0330] "GET /php/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:58:30 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:18:58:36 +0330] "GET /robots.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:58:43 +0330] "GET /shop.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:58:49 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:59:04 +0330] "GET /upload/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:59:10 +0330] "GET /vendor/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:59:49 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:59:50 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:59:50 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:59:50 +0330] "GET /wp-admin/css/colors/light/function.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:00:27 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:00:39 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:00:40 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:00:40 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:00:52 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:01:04 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:01:04 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:01:17 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:01:58 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:01:58 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:02:10 +0330] "GET /wp-content/Geforce.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:02:17 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:02:23 +0330] "GET /wp-content/autoload_classmap.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:02:30 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:02:30 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:02:30 +0330] "GET /wp-content/plugins/HelloDollyV2/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:02:37 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:02:44 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:02:50 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:18:59:17 +0330] "GET /wp-admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:59:24 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:18:59:36 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:00:03 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:00:03 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:00:03 +0330] "GET /wp-admin/includes/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:00:03 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:00:15 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:01:30 +0330] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:01:39 +0330] "GET /wp-blog-header.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:01:45 +0330] "GET /wp-comments.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:01:51 +0330] "GET /wp-conflg.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:03:12 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:03:13 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:18 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:03:18 +0330] "GET /wp-content/uploads/Geforce.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:02:57 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:02:57 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:03:04 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 500 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:05 +0330] "GET /wp-content/themes/themes.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:03:36 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:03:36 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:36 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:41 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:42 +0330] "GET /wp-includes/IXR/test1.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:03:48 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:48 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:03:49 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:04:07 +0330] "GET /wp-includes/SimplePie/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:04:17 +0330] "GET /wp-includes/SimplePie/chosen.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:04:24 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:04:29 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:25 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:30 +0330] "GET /wp-good.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:03:55 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:04:00 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:04:00 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:04:42 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:04:42 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:04:59 +0330] "GET /wp-includes/block-bindings/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:04:59 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:04:59 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:04:59 +0330] "GET /wp-includes/blocks/shortcode/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:05 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:05 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:05 +0330] "GET /wp-includes/css/dist/alam.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:11 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:11 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:17 +0330] "GET /wp-content/cache/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:23 +0330] "GET /wp-content/w3tc/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:05:30 +0330] "GET /wp-content/et-cache/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:36 +0330] "GET /wp-content/cache/supercache/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:41 +0330] "GET /wp-content/wflogs/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:41 +0330] "GET /wp-content/updraft/ HTTP/1.1" 200 112 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:05:41 +0330] "GET /wp-content/ai1wm-backups/ HTTP/1.1" 500 26 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:05:41 +0330] "GET /wp-content/backups-dup-lite/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:48 +0330] "GET /wp-content/backup-db/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:05:54 +0330] "GET /wp-content/uploads/woocommerce_uploads/ HTTP/1.1" 200 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:05:54 +0330] "GET /wp-content/uploads/woocommerce/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:06:08 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:06:13 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:13 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:06:13 +0330] "GET /wp-includes/images/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:06:37 +0330] "GET /wp-includes/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:04:29 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:04:29 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:04:30 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:04:30 +0330] "GET /wp-includes/Text/Diff/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:04:35 +0330] "GET /wp-includes/Text/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:04:49 +0330] "GET /wp-includes/bk/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:01 +0330] "GET /wp-content/uploads/wc-logs/ HTTP/1.1" 200 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:01 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:06:01 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:06:01 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:02 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:26 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:06:26 +0330] "GET /wp-includes/images/media/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:31 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:31 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:50 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:06:50 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:50 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:07:03 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:07:03 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:07:03 +0330] "GET /wp-includes/sodium_compat/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:07:08 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:07:09 +0330] "GET /wp-includes/style-engine/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:07:13 +0330] "GET /wp-includes/style-engine/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:07:20 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:07:20 +0330] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 172.192.16.167 - - [01/Dec/2025:19:08:08 +0330] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:13 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:21 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:25 +0330] "GET /file.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:29 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:33 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:38 +0330] "GET /admin.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:42 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:04 +0330] "GET /wp-includes/ID3/autoload_classmap.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:08 +0330] "GET /edit.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:12 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:17 +0330] "GET /wp-admin/css/colors/blue/atomlib.php HTTP/1.1" 301 0 "-" "-" 4.227.237.203 - - [01/Dec/2025:19:06:42 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:42 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:06:43 +0330] "GET /wp-includes/js/jcrop/jcrop.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:56 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:56 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:56 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:06:56 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:57 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:06:57 +0330] "GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.227.237.203 - - [01/Dec/2025:19:07:26 +0330] "GET /wp-mail.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.227.237.203 - - [01/Dec/2025:19:07:30 +0330] "GET /wp-signin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:07:35 +0330] "GET /wp-update.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:07:40 +0330] "GET /wp.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.227.237.203 - - [01/Dec/2025:19:07:46 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 172.192.16.167 - - [01/Dec/2025:19:08:51 +0330] "GET /wp-admin/css/colors/modern/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:51 +0330] "GET /wp-includes/pomo/about.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:56 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:08:56 +0330] "GET /wp-admin/js/autoload_classmap.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:04 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:04 +0330] "GET /wp-includes/css/dist/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:04 +0330] "GET /wp-admin/css/colors/sunrise/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:05 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:08 +0330] "GET /wp-content/about.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:13 +0330] "GET /.well-known/admin.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:18 +0330] "GET /wp-includes/js/tinymce/langs/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:18 +0330] "GET /templates/beez3/error.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:22 +0330] "GET /goods.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:26 +0330] "GET /wp-includes/autoload_classmap.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:30 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:31 +0330] "GET /1.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:35 +0330] "GET /wp-admin/js/widgets/cloud.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:05 +0330] "GET /ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:09 +0330] "GET /wp-admin/js/about.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:28 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:28 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:28 +0330] "GET /wp-includes/Requests/Text/ HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:33 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:37 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:38 +0330] "GET /aa.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:42 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:42 +0330] "GET /wp-includes/js/swfupload/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:42 +0330] "GET /file5.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:47 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:47 +0330] "GET /wp-includes/customize/chosen.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:51 +0330] "GET /admin/controller/extension/extension/ultra.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:55 +0330] "GET /wp-includes/assets/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:58 +0330] "GET /wp-includes/Text/wp-login.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:03 +0330] "GET /wp-admin/images/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:12 +0330] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:17 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:17 +0330] "GET /wp-admin/install.php HTTP/1.1" 403 17364 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:18 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:18 +0330] "GET /wp-admin/css/colors/blue/about.php HTTP/1.1" 301 0 "-" "-" 182.44.9.147 - - [01/Dec/2025:19:18:23 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 172.192.16.167 - - [01/Dec/2025:19:09:25 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:25 +0330] "GET /admin/uploads/ HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:30 +0330] "GET /flower.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:36 +0330] "GET /wp-error.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:40 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:40 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:40 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:45 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:45 +0330] "GET /wp/wp-admin/includes/ HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:49 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:50 +0330] "GET /wp-includes/IXR/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:53 +0330] "GET /.well-known/gecko-litespeed.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:09:57 +0330] "GET /templates/cassiopeia/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:43 +0330] "GET /index/function.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:48 +0330] "GET /about/function.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:52 +0330] "GET /functions.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:10:57 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:18 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:11:18 +0330] "GET /wp-admin/includes/cloud.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:27 +0330] "GET /plugins/ HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:32 +0330] "GET /radio.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:36 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:36 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:37 +0330] "GET /wp-admin/css/colors/coffee/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:37 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:38 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:38 +0330] "GET /wp-admin/autoload_classmap.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:50 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:50 +0330] "GET /wp-content/upgrade-temp-backup/about.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:55 +0330] "GET /wp-content/uploads/2024/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:12:59 +0330] "GET /wp-content/languages/chosen.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:03 +0330] "GET /images/class-config.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:08 +0330] "GET /wp-content/themes/wp-pridmag/init.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:12 +0330] "GET /wp-includes/images/smilies/index.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:16 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:23 +0330] "GET /wp-includes/js/tinymce/plugins/compat3x/css/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:23 +0330] "GET /wp-admin/wp-conflg.php HTTP/1.1" 301 0 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:32 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:32 +0330] "GET /wp-content/uploads/2022/ HTTP/1.1" 403 787 "-" "-" 172.192.16.167 - - [01/Dec/2025:19:13:32 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "-" "-" 27.66.19.70 - - [01/Dec/2025:19:49:12 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 185.2.4.95 - - [01/Dec/2025:19:45:57 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 4.241.208.113 - - [01/Dec/2025:19:49:34 +0330] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 141.98.11.181 - - [01/Dec/2025:20:12:35 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 141.98.11.181 - - [01/Dec/2025:20:12:56 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 141.98.11.181 - - [01/Dec/2025:20:13:02 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 141.98.11.181 - - [01/Dec/2025:20:13:14 +0330] "GET /login/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 152.42.185.229 - - [01/Dec/2025:21:03:24 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 103.54.36.57 - - [01/Dec/2025:22:42:05 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 45.132.49.182 - - [01/Dec/2025:22:44:33 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 4.189.161.198 - - [02/Dec/2025:00:03:28 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:03:28 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:03:28 +0330] "GET /.well-known/acme-challenge/xa.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:03:35 +0330] "GET /.well-known/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:03:40 +0330] "GET /1.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:03:52 +0330] "GET /aa.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:04:04 +0330] "GET /about.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:04:23 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:04:29 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:04:40 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:04:47 +0330] "GET /as.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:05:00 +0330] "GET /asd.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:05:05 +0330] "GET /assets/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:05:13 +0330] "GET /assets/images/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:05:19 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:05:26 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:05:33 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:03:46 +0330] "GET /403.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:03:57 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:04:10 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:04:17 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:04:34 +0330] "GET /alfa.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:04:53 +0330] "GET /asasx.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:05:40 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:05:47 +0330] "GET /dex.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:05:54 +0330] "GET /doc.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:06:01 +0330] "GET /ds.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:06:15 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:06:23 +0330] "GET /files/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:06:30 +0330] "GET /files/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:06:40 +0330] "GET /function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:06:54 +0330] "GET /gfile.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:07:02 +0330] "GET /gg.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 139.59.30.253 - - [02/Dec/2025:00:07:25 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:05:33 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:06:08 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:06:47 +0330] "GET /gelay.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:07:08 +0330] "GET /goods.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:07:15 +0330] "GET /i.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:07:22 +0330] "GET /images/images/about.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:07:29 +0330] "GET /images/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:07:34 +0330] "GET /inc.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:07:55 +0330] "GET /info.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:08:02 +0330] "GET /ini.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:08:09 +0330] "GET /inputs.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:08:24 +0330] "GET /item.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:08:31 +0330] "GET /manager.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.189.161.198 - - [02/Dec/2025:00:08:38 +0330] "GET /modules/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:08:45 +0330] "GET /moon.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:08:52 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:08:59 +0330] "GET /past.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:09:07 +0330] "GET /php/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:09:14 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:09:21 +0330] "GET /robots.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:09:28 +0330] "GET /shop.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:09:35 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:10:11 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:10:24 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:07:41 +0330] "GET /index.bak.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:07:48 +0330] "GET /index/function.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:08:17 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:09:41 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:09:48 +0330] "GET /upload/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:09:55 +0330] "GET /vendor/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:10:03 +0330] "GET /wp-admin.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:10:37 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:10:38 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:10:38 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:10:38 +0330] "GET /wp-admin/css/colors/light/function.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.189.161.198 - - [02/Dec/2025:00:11:04 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:11:20 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:11:47 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:11:59 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:11:59 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:12:12 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:12:37 +0330] "GET /wp-blog-header.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:12:42 +0330] "GET /wp-comments.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:13:04 +0330] "GET /wp-content/Geforce.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:13:11 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:13:26 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:13:26 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:10:51 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:10:51 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:10:52 +0330] "GET /wp-admin/includes/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:10:52 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:11:34 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:11:34 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:11:35 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.189.161.198 - - [02/Dec/2025:00:12:24 +0330] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:12:49 +0330] "GET /wp-conflg.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:12:57 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:12:57 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:13:20 +0330] "GET /wp-content/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:13:34 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:13:55 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:13:56 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:23 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:36 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:37 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:37 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:42 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:14:42 +0330] "GET /wp-includes/IXR/test1.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:50 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:50 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:50 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:10 +0330] "GET /wp-includes/SimplePie/autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:17 +0330] "GET /wp-includes/SimplePie/chosen.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:15:24 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:29 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:29 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:29 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:30 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:30 +0330] "GET /wp-includes/Text/Diff/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:13:27 +0330] "GET /wp-content/plugins/HelloDollyV2/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:13:41 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:13:48 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:03 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 500 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:03 +0330] "GET /wp-content/themes/themes.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:14:10 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:11 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:16 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:16 +0330] "GET /wp-content/uploads/Geforce.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:29 +0330] "GET /wp-good.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:14:57 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:03 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:15:03 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:36 +0330] "GET /wp-includes/Text/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:50 +0330] "GET /wp-includes/bk/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:15 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:43 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:15:43 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:01 +0330] "GET /wp-includes/block-bindings/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:16:01 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:01 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:02 +0330] "GET /wp-includes/blocks/shortcode/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:16:08 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:16:08 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:16:08 +0330] "GET /wp-includes/css/dist/alam.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:35 +0330] "GET /wp-content/et-cache/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:03 +0330] "GET /wp-content/uploads/woocommerce_uploads/ HTTP/1.1" 200 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:17:03 +0330] "GET /wp-content/uploads/woocommerce/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 62.60.130.228 - - [02/Dec/2025:00:17:14 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Gecko/20100101 Firefox/119.0.1" 4.189.161.198 - - [02/Dec/2025:00:17:18 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:23 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:17:23 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:16 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:16:21 +0330] "GET /wp-content/cache/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:28 +0330] "GET /wp-content/w3tc/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:41 +0330] "GET /wp-content/cache/supercache/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:48 +0330] "GET /wp-content/wflogs/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:48 +0330] "GET /wp-content/updraft/ HTTP/1.1" 200 112 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:16:48 +0330] "GET /wp-content/ai1wm-backups/ HTTP/1.1" 500 26 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:16:49 +0330] "GET /wp-content/backups-dup-lite/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:16:56 +0330] "GET /wp-content/backup-db/ HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:10 +0330] "GET /wp-content/uploads/wc-logs/ HTTP/1.1" 200 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:10 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:17:10 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:11 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:17:11 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:53 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:53 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:17:24 +0330] "GET /wp-includes/images/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:29 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:29 +0330] "GET /wp-includes/images/media/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:34 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:34 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:40 +0330] "GET /wp-includes/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:45 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:46 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:46 +0330] "GET /wp-includes/js/jcrop/jcrop.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:00 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:18:00 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:01 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:01 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:01 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:18:01 +0330] "GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:08 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:09 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:09 +0330] "GET /wp-includes/sodium_compat/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:13 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:14 +0330] "GET /wp-includes/style-engine/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.189.161.198 - - [02/Dec/2025:00:18:19 +0330] "GET /wp-includes/style-engine/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.189.161.198 - - [02/Dec/2025:00:18:26 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:26 +0330] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:18:50 +0330] "GET /wp.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:57 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:17:54 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.189.161.198 - - [02/Dec/2025:00:18:33 +0330] "GET /wp-mail.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:37 +0330] "GET /wp-signin.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.189.161.198 - - [02/Dec/2025:00:18:44 +0330] "GET /wp-update.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 2.58.56.122 - - [02/Dec/2025:01:10:16 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" 175.6.217.4 - - [02/Dec/2025:01:16:15 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 45.156.128.171 - - [02/Dec/2025:01:46:25 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:46:56 +0330] "GET /license.txt HTTP/1.1" 200 7276 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:47:17 +0330] "GET /wp-content/plugins/wordpress-database-reset/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:47:44 +0330] "GET /wp-content/plugins/wp-time-capsule/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:07 +0330] "GET /wp-content/plugins/code-snippets/readme.txt HTTP/1.1" 200 6180 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/all-in-one-wp-migration/readme.txt HTTP/1.1" 200 5044 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/akismet/readme.txt HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/elementor/readme.txt HTTP/1.1" 200 10067 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/google-site-kit/readme.txt HTTP/1.1" 200 4129 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/really-simple-ssl/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/contact-form-7/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/seo-by-rank-math/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/duplicate-page/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/hostinger/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/litespeed-cache/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/updraftplus/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/wpforms-lite/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/header-footer-elementor/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/advanced-custom-fields/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/wps-hide-login/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/google-analytics-for-wordpress/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/wp-super-cache/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/duplicate-post/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/disable-comments/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/svg-support/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/limit-login-attempts-reloaded/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/loginizer/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/envato-elements/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/wp-fastest-cache/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/complianz-gdpr/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/w3-total-cache/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/ewww-image-optimizer/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:46:53 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:46:54 +0330] "GET /aspera/faspex/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:46:55 +0330] "GET /favicon.ico HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/wordpress-seo/readme.txt HTTP/1.1" 200 7289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/essential-addons-for-elementor-lite/readme.txt HTTP/1.1" 200 15892 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/wordfence/readme.txt HTTP/1.1" 200 15574 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/mailchimp-for-wp/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/insert-headers-and-footers/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/jetpack/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/better-search-replace/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/all-in-one-seo-pack/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/duplicator/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/redirection/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/astra-sites/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:21 +0330] "GET /wp-content/plugins/wp-optimize/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/autoptimize/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/redux-framework/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/better-wp-security/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/sg-security/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/smart-slider-3/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/coming-soon/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.171 - - [02/Dec/2025:01:48:22 +0330] "GET /wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:48:59 +0330] "GET /wp-content/plugins/kingcomposer/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:49:21 +0330] "GET /wp-content/plugins/optinmonster/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:49:45 +0330] "GET /wp-content/plugins/bbpress/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.170 - - [02/Dec/2025:01:50:12 +0330] "GET /wp-content/plugins/fancy-product-designer/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:50:48 +0330] "GET /wp-content/plugins/wp-user-avatar/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:51:58 +0330] "GET /wp-content/plugins/wp-central/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 91.231.89.123 - - [02/Dec/2025:02:05:11 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0" 45.156.128.171 - - [02/Dec/2025:01:52:47 +0330] "GET /wp-content/plugins/wpschoolpress/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.169 - - [02/Dec/2025:01:53:07 +0330] "GET /wp-content/plugins/wp-video-lightbox/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.168 - - [02/Dec/2025:01:53:26 +0330] "GET /wp-content/plugins/iwp-client/readme.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 91.196.152.154 - - [02/Dec/2025:02:12:47 +0330] "GET /favicon.ico HTTP/1.1" 404 796 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0" 47.128.59.110 - - [02/Dec/2025:02:36:16 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 108.181.30.195 - - [02/Dec/2025:02:38:21 +0330] "GET / HTTP/1.1" 301 20 "-" "python-requests/2.32.5" 51.89.199.115 - - [02/Dec/2025:02:42:32 +0330] "GET /userfuns.php HTTP/1.1" 403 6887 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.77.106.81 - - [02/Dec/2025:02:48:25 +0330] "GET /sftp-config.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 103.77.106.81 - - [02/Dec/2025:02:48:31 +0330] "GET /.vscode/sftp.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 51.89.199.115 - - [02/Dec/2025:02:42:33 +0330] "GET /postnews.php HTTP/1.1" 403 6888 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 43.153.123.3 - - [02/Dec/2025:03:26:02 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 59.153.19.170 - - [02/Dec/2025:04:14:07 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 14.235.61.57 - - [02/Dec/2025:05:01:17 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 43.130.111.40 - - [02/Dec/2025:05:23:01 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 170.106.165.186 - - [02/Dec/2025:05:20:35 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 43.157.153.236 - - [02/Dec/2025:05:40:16 +0330] "GET /sevices/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 43.166.255.102 - - [02/Dec/2025:06:30:12 +0330] "GET /academic-co-working/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 110.166.71.39 - - [02/Dec/2025:07:19:34 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 185.77.216.27 - - [02/Dec/2025:08:32:38 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36" 82.118.29.234 - - [02/Dec/2025:09:06:19 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 134.199.220.179 - - [02/Dec/2025:09:43:32 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0" 5.189.188.71 - - [02/Dec/2025:10:03:43 +0330] "GET /postnews.php HTTP/1.1" 301 20 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 5.189.188.71 - - [02/Dec/2025:10:03:56 +0330] "GET /ss.php?f_c=1 HTTP/1.1" 301 20 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 5.189.188.71 - - [02/Dec/2025:10:03:10 +0330] "GET /postnews.php HTTP/1.1" 301 20 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 107.172.190.233 - - [02/Dec/2025:11:23:27 +0330] "GET /xmlrpc.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 43.135.145.117 - - [02/Dec/2025:12:20:16 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:33:03 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:33:03 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:33:03 +0330] "GET /.well-known/acme-challenge/xa.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:33:12 +0330] "GET /.well-known/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:33:16 +0330] "GET /1.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:33:23 +0330] "GET /403.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:12:33:29 +0330] "GET /aa.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:33:36 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:33:51 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:34:07 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:34:15 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:34:23 +0330] "GET /alfa.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:34:38 +0330] "GET /as.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:35:02 +0330] "GET /assets/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:35:11 +0330] "GET /assets/images/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:35:29 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:36:03 +0330] "GET /doc.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:33:43 +0330] "GET /about.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:33:58 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:12:34:30 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:34:46 +0330] "GET /asasx.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:34:54 +0330] "GET /asd.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:35:20 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:35:37 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:35:38 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:35:46 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:35:54 +0330] "GET /dex.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:12:36:26 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:36:34 +0330] "GET /files/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:36:56 +0330] "GET /function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:36:11 +0330] "GET /ds.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:36:19 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:36:44 +0330] "GET /files/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:37:04 +0330] "GET /gelay.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:37:20 +0330] "GET /gg.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:37:36 +0330] "GET /i.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:37:45 +0330] "GET /images/images/about.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:37:52 +0330] "GET /images/index.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:37:59 +0330] "GET /inc.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:12:38:06 +0330] "GET /index.bak.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:38:23 +0330] "GET /info.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:38:38 +0330] "GET /inputs.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:39:02 +0330] "GET /manager.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:39:34 +0330] "GET /past.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:39:50 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:39:58 +0330] "GET /robots.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:40:06 +0330] "GET /shop.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:40:22 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:40:31 +0330] "GET /upload/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:40:39 +0330] "GET /vendor/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:37:11 +0330] "GET /gfile.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:37:28 +0330] "GET /goods.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:38:15 +0330] "GET /index/function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:38:30 +0330] "GET /ini.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:38:46 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:38:54 +0330] "GET /item.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:39:10 +0330] "GET /modules/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:39:18 +0330] "GET /moon.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:39:26 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:39:42 +0330] "GET /php/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:40:14 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:41:52 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:42:19 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:42:19 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:42:20 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:12:42:34 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:42:48 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:40:47 +0330] "GET /wp-admin.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:40:55 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:41:09 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:41:22 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:41:23 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:41:23 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:41:23 +0330] "GET /wp-admin/css/colors/light/function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:41:37 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:41:37 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:41:38 +0330] "GET /wp-admin/includes/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:41:38 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:42:06 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:43:02 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:43:15 +0330] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:43:27 +0330] "GET /wp-blog-header.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:43:32 +0330] "GET /wp-comments.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:42:48 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:43:40 +0330] "GET /wp-conflg.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:12:43:48 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:43:49 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:12:43:57 +0330] "GET /wp-content/Geforce.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:44:05 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:44:13 +0330] "GET /wp-content/autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:44:22 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:12:44:22 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:12:44:22 +0330] "GET /wp-content/plugins/HelloDollyV2/ HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 194.195.91.1 - - [02/Dec/2025:12:57:24 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36" 43.173.1.57 - - [02/Dec/2025:13:21:17 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 196.251.100.176 - - [02/Dec/2025:13:39:00 +0330] "GET /assets/jquery-file-upload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 403 17364 "-" "ALittle Client" 180.110.203.108 - - [02/Dec/2025:13:59:48 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 157.173.101.17 - - [02/Dec/2025:15:11:46 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 185.181.245.142 - - [02/Dec/2025:15:13:06 +0330] "GET /robots.txt HTTP/1.0" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36/Nutch-1.21-SNAPSHOT" 185.254.75.35 - - [02/Dec/2025:15:28:49 +0330] "GET /wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_2_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" 104.28.246.113 - - [02/Dec/2025:16:03:42 +0330] "GET /style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 104.28.214.112 - - [02/Dec/2025:16:03:50 +0330] "GET /wp-content/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 4.241.192.251 - - [02/Dec/2025:16:44:01 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:44:07 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:44:27 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:44:34 +0330] "GET /xmlrpc.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:44:38 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:44:51 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:44:51 +0330] "GET /cgi-bin/file.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:45:05 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:45:33 +0330] "GET /NewFile.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:16:45:40 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:46:01 +0330] "GET /info.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:46:08 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:46:23 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:46:30 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:46:42 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:47:07 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:44:13 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:44:20 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:44:45 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:44:58 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:45:12 +0330] "GET /cong.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:45:19 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:45:26 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:45:47 +0330] "GET /file5.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:45:54 +0330] "GET /gel4y.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:46:15 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:46:54 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:47:33 +0330] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:47:45 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:48:12 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:48:17 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:48:22 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:48:22 +0330] "GET /wp-good.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:48:27 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:48:27 +0330] "GET /wp-includes/SimplePie/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:48:32 +0330] "GET /wp-includes/SimplePie/chosen.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:48:50 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:48:55 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:48:56 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:48:56 +0330] "GET /wp-includes/rest-api/search/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:49:00 +0330] "GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:47:07 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:47:08 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:47:20 +0330] "GET /wp-admin/js/wp-login.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:47:52 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:47:59 +0330] "GET /wp-content/et-cache/ HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:48:05 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:48:06 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:48:38 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [02/Dec/2025:16:48:44 +0330] "GET /wp-includes/css/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:49:05 +0330] "GET /wp-includes/style-engine/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:49:11 +0330] "GET /wp-includes/style-engine/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:49:17 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [02/Dec/2025:16:49:17 +0330] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [02/Dec/2025:16:49:23 +0330] "GET /wp.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 91.90.123.62 - - [02/Dec/2025:17:06:01 +0330] "GET / HTTP/1.1" 403 6888 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0" 50.225.46.13 - - [02/Dec/2025:17:26:22 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 85.194.44.225 - - [02/Dec/2025:17:48:28 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 49.214.255.129 - - [02/Dec/2025:17:58:29 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 43.130.40.120 - - [02/Dec/2025:18:30:59 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:18:43:32 +0330] "GET //simi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:43:39 +0330] "GET //rest.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:43:50 +0330] "GET //sx21_1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:10 +0330] "GET //zone.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:16 +0330] "GET //zonexx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:22 +0330] "GET //403webshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:35 +0330] "GET //O-Simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:42 +0330] "GET //ObeQY2t7P.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:48 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:45:02 +0330] "GET //berax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:45:09 +0330] "GET //ckmail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:45:26 +0330] "GET //click.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:45:38 +0330] "GET //database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:45:44 +0330] "GET //database.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:45:51 +0330] "GET //db.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:43:46 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:43:56 +0330] "GET //login.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:03 +0330] "GET //Jada.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:28 +0330] "GET //MuPlugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:44:55 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:45:32 +0330] "GET //csv.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:45:57 +0330] "GET //defaults.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:11 +0330] "GET //ex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:24 +0330] "GET //f8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:31 +0330] "GET //fix.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:37 +0330] "GET //fix.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:43 +0330] "GET //goods.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:51 +0330] "GET //inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:58 +0330] "GET //item.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:47:11 +0330] "GET //asmtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:47:29 +0330] "GET //about.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:47:36 +0330] "GET //chosen.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:47:42 +0330] "GET //content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:48:02 +0330] "GET //y.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:48:29 +0330] "GET //e.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:48:36 +0330] "GET //zz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 89.163.146.197 - - [02/Dec/2025:18:48:40 +0330] "GET /about.php?action=p&api=p&path=p&token= HTTP/1.1" 403 6887 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.155.161.47 - - [02/Dec/2025:18:48:42 +0330] "GET //aa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:48:49 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:48:56 +0330] "GET //wordpress.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:09 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:29 +0330] "GET //ninjasec.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:04 +0330] "GET //documentroot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:46:17 +0330] "GET //execlude.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:47:05 +0330] "GET //mah.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:47:21 +0330] "GET //malro.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:47:49 +0330] "GET //shop.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:47:55 +0330] "GET //r.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:48:09 +0330] "GET //a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:48:16 +0330] "GET //b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:48:23 +0330] "GET //c.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:02 +0330] "GET //core.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:16 +0330] "GET //zossipei.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:23 +0330] "GET //lf_utchiha.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:36 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:43 +0330] "GET //alfanew.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:57 +0330] "GET //utchiha_offer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:50:14 +0330] "GET //shell-script.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:50:33 +0330] "GET //simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:50:49 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:50:56 +0330] "GET //xleet.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:51:03 +0330] "GET //rain.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:51:10 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:51:16 +0330] "GET //dnvokikk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:51:30 +0330] "GET //contents.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:51:37 +0330] "GET //copy.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:51:43 +0330] "GET //fw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:51:50 +0330] "GET //ae.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:03 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:10 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:18 +0330] "GET //srx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:25 +0330] "GET //1337.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:31 +0330] "GET //ups.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:45 +0330] "GET //xx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:52 +0330] "GET //leaf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:59 +0330] "GET //leafmailer2.8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:53:05 +0330] "GET //lf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:53:12 +0330] "GET //alex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:53:31 +0330] "GET //mailer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:00 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:07 +0330] "GET //1index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:20 +0330] "GET //wikindex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:27 +0330] "GET //wso1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:33 +0330] "GET //alfa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:49:50 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:50:03 +0330] "GET //style.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:50:10 +0330] "GET //xmlrpc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:50:22 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:50:43 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:51:56 +0330] "GET //glppziux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:52:38 +0330] "GET //doc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:53:19 +0330] "GET //new.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:53:44 +0330] "GET //marijuana.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:53:52 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:14 +0330] "GET //3index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:39 +0330] "GET //priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:46 +0330] "GET //bb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:58 +0330] "GET //Lux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:55:05 +0330] "GET //haxor.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:55:11 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:55:24 +0330] "GET //send.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:55:30 +0330] "GET //uplo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:55:49 +0330] "GET //wp-content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:07 +0330] "GET //404.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:13 +0330] "GET //asad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:26 +0330] "GET //smtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:33 +0330] "GET //azerty.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:39 +0330] "GET //dell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:57:06 +0330] "GET //cpn.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:57:26 +0330] "GET //madspot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:57:34 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:57:41 +0330] "GET //cpbt.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:57:55 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:29 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:37 +0330] "GET //shellz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:43 +0330] "GET //d0main.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:50 +0330] "GET //d0mains.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:54:52 +0330] "GET //m.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:55:17 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:55:36 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 142.93.235.15 - - [02/Dec/2025:18:55:41 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 105.155.161.47 - - [02/Dec/2025:18:55:43 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:55:56 +0330] "GET //wp-upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:03 +0330] "GET //wp-mail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:20 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:46 +0330] "GET //WSO.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:52 +0330] "GET //dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:56:59 +0330] "GET //cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:57:13 +0330] "GET //sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:57:20 +0330] "GET //mysql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:57:48 +0330] "GET //sYm.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:02 +0330] "GET //r99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:09 +0330] "GET //lol.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:16 +0330] "GET //jo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:23 +0330] "GET //wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:58:57 +0330] "GET /users.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:59:08 +0330] "GET //killer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:59:15 +0330] "GET //changeall.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:59:22 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:59:01 +0330] "GET //Cgishell.pl HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:59:32 +0330] "GET //Sh3ll.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:59:42 +0330] "GET //dz0.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:59:56 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:25 +0330] "GET //c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:32 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:45 +0330] "GET //wp.zip HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:03 +0330] "GET //c22.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:09 +0330] "GET //c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:16 +0330] "GET //Cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:40 +0330] "GET /L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:45 +0330] "GET /d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:50 +0330] "GET /tmp/d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:14 +0330] "GET /admin2.asp HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:18 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:23 +0330] "GET /sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:42 +0330] "GET /images/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:12 +0330] "GET //sa2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:19 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:26 +0330] "GET /gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:30 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:35 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:18:59:49 +0330] "GET //dam.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:04 +0330] "GET //dom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:11 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:18 +0330] "GET //r00t.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:39 +0330] "GET //1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:52 +0330] "GET /madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:00:57 +0330] "GET //Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:23 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:34 +0330] "GET //madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:01:54 +0330] "GET /tmp/L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:00 +0330] "GET /admin1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:04 +0330] "GET /upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:10 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:27 +0330] "GET /sysadmins/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:32 +0330] "GET /admin1/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:36 +0330] "GET /administration/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:46 +0330] "GET //r57.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:52 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:02:59 +0330] "GET //sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:06 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:46 +0330] "GET /shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:55 +0330] "GET /t00.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:42 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:03:50 +0330] "GET /amad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:10 +0330] "GET /asp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:19 +0330] "GET /d0maine.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:24 +0330] "GET /tmp/sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:29 +0330] "GET /tmp/dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:33 +0330] "GET /dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:43 +0330] "GET /wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:52 +0330] "GET /images/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:01 +0330] "GET /c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:06 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:10 +0330] "GET /Server.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:32 +0330] "GET /admins.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:40 +0330] "GET /a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:54 +0330] "GET /1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:09 +0330] "GET /4.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:13 +0330] "GET /5.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:18 +0330] "GET /6.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:23 +0330] "GET /amhlzdhk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:28 +0330] "GET /balance.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:33 +0330] "GET /curl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:37 +0330] "GET /database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:00 +0330] "GET /dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:05 +0330] "GET /Black.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:15 +0330] "GET /whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:38 +0330] "GET /Symlink.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:47 +0330] "GET /sysadmin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:04:56 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:14 +0330] "GET /wp-admin/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:22 +0330] "GET /tmp/priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:27 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:48 +0330] "GET /w.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:05:59 +0330] "GET /2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:04 +0330] "GET /3.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:41 +0330] "GET /hyivatpf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:08 +0330] "GET /slax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:13 +0330] "GET /tesTlme.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:18 +0330] "GET /todo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:27 +0330] "GET /txfpcuhw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:31 +0330] "GET /unzipper.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:54 +0330] "GET /utchiha2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:04 +0330] "GET /webhook.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:16 +0330] "GET /wp-pano.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:21 +0330] "GET /wqjtejxi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:46 +0330] "GET /index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:53 +0330] "GET /inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:06:58 +0330] "GET /nf_tracking.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:03 +0330] "GET /qkyplyur.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:22 +0330] "GET /ttcecnmc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:38 +0330] "GET /unZIPpeRqyr.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:47 +0330] "GET /ut.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:07:59 +0330] "GET /uuhoxcyb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:08 +0330] "GET /wp-atom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:30 +0330] "GET /zvpqaqfb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:41 +0330] "GET //shadow.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:26 +0330] "GET /wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:35 +0330] "GET //xl2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:19:08:48 +0330] "GET //plugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 194.54.144.105 - - [02/Dec/2025:19:23:28 +0330] "GET /manager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:30 +0330] "GET /bless.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:23:31 +0330] "GET /O-Simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.54.144.105 - - [02/Dec/2025:19:23:32 +0330] "GET /lock360.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:33 +0330] "GET /zwso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.54.144.105 - - [02/Dec/2025:19:23:34 +0330] "GET /chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:36 +0330] "GET /about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.54.144.105 - - [02/Dec/2025:19:23:37 +0330] "GET /admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:38 +0330] "GET /.well-known/login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:39 +0330] "GET /mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:40 +0330] "GET /.wp/wso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:23:42 +0330] "GET /core.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:23:43 +0330] "GET /robots.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:44 +0330] "GET /inputs.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.54.144.105 - - [02/Dec/2025:19:23:45 +0330] "GET /mini.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:46 +0330] "GET /goods.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:48 +0330] "GET /file5.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:23:49 +0330] "GET /ahax.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:50 +0330] "GET /f35.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:51 +0330] "GET /simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.54.144.105 - - [02/Dec/2025:19:23:52 +0330] "GET /update/f35.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.54.144.105 - - [02/Dec/2025:19:23:53 +0330] "GET /wp-content/hello.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:55 +0330] "GET /wp-admin/maint/bootstrap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:56 +0330] "GET /themes/zMousse/otuz1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.54.144.105 - - [02/Dec/2025:19:23:57 +0330] "GET /wp-content/edit-wolf.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:23:58 +0330] "GET /wp-content/plugins/ubh/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.54.144.105 - - [02/Dec/2025:19:23:59 +0330] "GET /wp-admin/images/bootstrap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:24:01 +0330] "GET /images/upload.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.54.144.105 - - [02/Dec/2025:19:24:02 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.54.144.105 - - [02/Dec/2025:19:24:03 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:04 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:05 +0330] "GET /admin/uploads/bn_1_1754420677.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.54.144.105 - - [02/Dec/2025:19:24:07 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.54.144.105 - - [02/Dec/2025:19:24:08 +0330] "GET /wp-content/plugins/pwnd/pwnd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:09 +0330] "GET /wp-content/plugins/pwnd-1/pwnd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.54.144.105 - - [02/Dec/2025:19:24:10 +0330] "GET /wp-admin/css/colors/midnight/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:11 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/kill.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:12 +0330] "GET /wp-includes/style-engine/worksec.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:14 +0330] "GET /wp-admin/images/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:15 +0330] "GET /wp-content/plugins/core-plugin/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.54.144.105 - - [02/Dec/2025:19:24:16 +0330] "GET /wp-content/plugins/envato-css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:17 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:18 +0330] "GET /uploads/94056-upload.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:19 +0330] "GET /index/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:21 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:22 +0330] "GET /js/bas.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:23 +0330] "GET /.well-known/pki-validation/moon.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.54.144.105 - - [02/Dec/2025:19:24:23 +0330] "GET /file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:24 +0330] "GET /wp-includes/js/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:26 +0330] "GET /wp-content/upgrade/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:27 +0330] "GET /buy.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:28 +0330] "GET /wp-content/languages/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.54.144.105 - - [02/Dec/2025:19:24:29 +0330] "GET /wp-content/themes/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.54.144.105 - - [02/Dec/2025:19:24:30 +0330] "GET /wp-content/plugins/elementor/wp-wjvngrh.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.54.144.105 - - [02/Dec/2025:19:24:31 +0330] "GET /wp-includes/IXR/fix.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:33 +0330] "GET /wp-includes/widgets/dyqvcfqv.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:34 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:35 +0330] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:36 +0330] "GET /wp-includes/js/crop/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:37 +0330] "GET /wp-includes/PHPMailer/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.54.144.105 - - [02/Dec/2025:19:24:39 +0330] "GET /wp-includes/PHPMailer/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:40 +0330] "GET /wp-includes/widgets/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.54.144.105 - - [02/Dec/2025:19:24:41 +0330] "GET /files/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.54.144.105 - - [02/Dec/2025:19:24:42 +0330] "GET /wp-includes/PHPMailer/options.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.54.144.105 - - [02/Dec/2025:19:24:44 +0330] "GET /inc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.54.144.105 - - [02/Dec/2025:19:24:45 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:45 +0330] "GET /filemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:46 +0330] "GET /cgi-bin/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:48 +0330] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.54.144.105 - - [02/Dec/2025:19:24:48 +0330] "GET /wp-includes/IXR/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:24:49 +0330] "GET /wp-admin/js/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:50 +0330] "GET /wp-includes/js/jquery/jquery.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:24:51 +0330] "GET /function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.54.144.105 - - [02/Dec/2025:19:24:52 +0330] "GET /wp-includes/block-supports/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:54 +0330] "GET /wp-signup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.54.144.105 - - [02/Dec/2025:19:24:55 +0330] "GET /wp-admin/network/network.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.54.144.105 - - [02/Dec/2025:19:24:56 +0330] "GET /admin/upload/css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.54.144.105 - - [02/Dec/2025:19:24:57 +0330] "GET /wp-blog.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:24:58 +0330] "GET /wp-admin/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:00 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:25:01 +0330] "GET /wp-includes/blocks/table/int/tmpl/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.54.144.105 - - [02/Dec/2025:19:25:02 +0330] "GET /wp-l0gin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.54.144.105 - - [02/Dec/2025:19:25:04 +0330] "GET /wp-includes/js/jquery/suggest.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:25:05 +0330] "GET /new.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.54.144.105 - - [02/Dec/2025:19:25:06 +0330] "GET /wp-content/plugins/pwnd-1/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:07 +0330] "GET /wp-includes/defaults.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:25:09 +0330] "GET /images/DJP9.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:25:10 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.54.144.105 - - [02/Dec/2025:19:25:11 +0330] "GET /wp-admin/shell20211028.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:12 +0330] "GET /natural.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.54.144.105 - - [02/Dec/2025:19:25:13 +0330] "GET /item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:15 +0330] "GET /function/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:16 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:17 +0330] "GET /wp-admin/images/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:25:18 +0330] "GET /wp-includes/theme-compat/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:19 +0330] "GET /about/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 194.54.144.105 - - [02/Dec/2025:19:25:21 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:22 +0330] "GET /wp-includes/ID3/about.php/wp-content/x/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:23 +0330] "GET /wp-includes/ID3/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:25 +0330] "GET /wp-content/languages/404.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.54.144.105 - - [02/Dec/2025:19:25:26 +0330] "GET /update/403.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.54.144.105 - - [02/Dec/2025:19:25:27 +0330] "GET /default.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.54.144.105 - - [02/Dec/2025:19:25:28 +0330] "GET /wp-includes/assets/info.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:29 +0330] "GET /wp-includes/class.api.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.54.144.105 - - [02/Dec/2025:19:25:30 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.54.144.105 - - [02/Dec/2025:19:25:31 +0330] "GET /wp-admin/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:33 +0330] "GET /autoload_classmap/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:34 +0330] "GET /dropdown.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:35 +0330] "GET /images/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:36 +0330] "GET /db.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:25:37 +0330] "GET /.well-known/pki-validation/mariju.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:37 +0330] "GET /mah/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:39 +0330] "GET /wp-content/plugins/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.54.144.105 - - [02/Dec/2025:19:25:40 +0330] "GET /wp-includes/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:41 +0330] "GET /wp-content/themes/tflow/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.54.144.105 - - [02/Dec/2025:19:25:43 +0330] "GET /wp-admin/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:44 +0330] "GET /templates/beez3/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:45 +0330] "GET /wp-admin/js/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:46 +0330] "GET /install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:47 +0330] "GET /wp-admin/css/colors/blue/rk2.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:49 +0330] "GET /images/class-config.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:25:50 +0330] "GET /components/com_jea/views/form/tmpl/size.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:51 +0330] "GET /templates/beez/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:52 +0330] "GET /bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:25:53 +0330] "GET /class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:54 +0330] "GET /wp-admin/css/colors/light/profile.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:55 +0330] "GET /wp-content/product.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:25:57 +0330] "GET /wp-content/uploads/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.54.144.105 - - [02/Dec/2025:19:25:58 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ask.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:25:59 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:26:00 +0330] "GET /css/css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:01 +0330] "GET /init.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 194.54.144.105 - - [02/Dec/2025:19:26:02 +0330] "GET /wp-admin/user/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:04 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:26:05 +0330] "GET /wp-includes/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.54.144.105 - - [02/Dec/2025:19:26:06 +0330] "GET /assets/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:07 +0330] "GET /.well-known/pki-validation/index.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:07 +0330] "GET /wp-content/uploads/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:09 +0330] "GET /css/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:10 +0330] "GET /adminfuns.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:26:11 +0330] "GET /wp-admin/css/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:12 +0330] "GET /wp_wlx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.54.144.105 - - [02/Dec/2025:19:26:14 +0330] "GET /wp-admin/js/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 194.54.144.105 - - [02/Dec/2025:19:26:15 +0330] "GET /wp-includes/assets/husky301.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.54.144.105 - - [02/Dec/2025:19:26:16 +0330] "GET /wp.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:26:17 +0330] "GET /wp-admin/css/colors/blue/wp-trackback.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:26:18 +0330] "GET /wp-content/themes/chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:19 +0330] "GET /wp-header.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:26:20 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:26:22 +0330] "GET /Marvins.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:23 +0330] "GET /wp-content/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:24 +0330] "GET /wp-class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:26 +0330] "GET /wp-includes/images/smilies/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:26:27 +0330] "GET /xx.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:28 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:29 +0330] "GET /wp-includes/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 194.54.144.105 - - [02/Dec/2025:19:26:30 +0330] "GET /wp-content/blue.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.54.144.105 - - [02/Dec/2025:19:26:32 +0330] "GET /content.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:33 +0330] "GET /wp-content/uploads/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 194.54.144.105 - - [02/Dec/2025:19:26:34 +0330] "GET /wp-admin/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:35 +0330] "GET /wp-includes/rest-api/endpoints/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.54.144.105 - - [02/Dec/2025:19:26:36 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.54.144.105 - - [02/Dec/2025:19:26:37 +0330] "GET /wp-content/plugins/wp-theme-editor/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.54.144.105 - - [02/Dec/2025:19:26:39 +0330] "GET /wp-content/plugins/up/main.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:40 +0330] "GET /fonts/fontawesome-webfont.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:26:41 +0330] "GET /wp-admin/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.54.144.105 - - [02/Dec/2025:19:26:42 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:43 +0330] "GET /wp-admin/css/colors/blue/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 194.54.144.105 - - [02/Dec/2025:19:26:44 +0330] "GET /images/images/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.54.144.105 - - [02/Dec/2025:19:26:46 +0330] "GET /images/class.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 194.54.144.105 - - [02/Dec/2025:19:26:47 +0330] "GET /wp-content/plugins/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:48 +0330] "GET /web.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:50 +0330] "GET /wp-admin/css/colors/ocean/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:51 +0330] "GET /images/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:52 +0330] "GET /wp-content/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.54.144.105 - - [02/Dec/2025:19:26:53 +0330] "GET /.well-known/gecko-litespeed.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 194.54.144.105 - - [02/Dec/2025:19:26:54 +0330] "GET /wp-admin/css/colors/midnight/install.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:55 +0330] "GET /wp-trackback.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:56 +0330] "GET /wp-includes/style-engine/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:58 +0330] "GET /radio.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:23 +0330] "GET /wp-includes/css/dist/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:23 +0330] "GET /wp-includes/js/dist/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:23 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:23 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:23 +0330] "GET /wp-content/plugins/erinyani/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:25 +0330] "GET /wp-includes/l10n/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 89.187.177.123 - - [02/Dec/2025:19:27:25 +0330] "GET /wp-content/uploads/2023/11/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:25 +0330] "GET /wp-includes/sodium_compat/lib/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:25 +0330] "GET /wp-includes/blocks/file/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 89.187.177.123 - - [02/Dec/2025:19:27:25 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 89.187.177.123 - - [02/Dec/2025:19:27:25 +0330] "GET /wp-includes/block-bindings/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:26 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:27:26 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 89.187.177.123 - - [02/Dec/2025:19:27:26 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 89.187.177.123 - - [02/Dec/2025:19:27:27 +0330] "GET /wp-admin/css/colors/sunrise/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:27:27 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:28 +0330] "GET /wp-content/plugins/ioxi/ioxi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 89.187.177.123 - - [02/Dec/2025:19:27:29 +0330] "GET /wp-includes/id3/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:30 +0330] "GET /wp-includes/blocks/query/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:30 +0330] "GET /wp-includes/js/tinymce/langs/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:31 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:31 +0330] "GET /wp-includes/blocks/group/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 89.187.177.123 - - [02/Dec/2025:19:27:31 +0330] "GET /blog/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:27:32 +0330] "GET /wp-content/themes/twentytwentyfour/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 89.187.177.123 - - [02/Dec/2025:19:27:33 +0330] "GET /wp-includes/interactivity-api/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:34 +0330] "GET /wp-includes/wp-class.php/wp-content/themes/travelscape/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:27:35 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 89.187.177.123 - - [02/Dec/2025:19:27:35 +0330] "GET /wp-admin/js/dist/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:27:36 +0330] "GET /assets/css/dist/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:37 +0330] "GET /wp-includes/js/jquery/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:38 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 89.187.177.123 - - [02/Dec/2025:19:27:38 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 89.187.177.123 - - [02/Dec/2025:19:27:38 +0330] "GET /wp-content/plugins/wp-file-manager/admin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:39 +0330] "GET /wp-admin/js/widget/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:27:40 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:27:41 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:42 +0330] "GET /wp-content/themes/tflow/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:27:43 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:44 +0330] "GET /wordpress/wp-admin/includes HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:26:59 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:27:00 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.54.144.105 - - [02/Dec/2025:19:27:01 +0330] "GET /wp-admin/css/colors/midnight/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.54.144.105 - - [02/Dec/2025:19:27:02 +0330] "GET /wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:27:03 +0330] "GET /wp-setup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 194.54.144.105 - - [02/Dec/2025:19:27:04 +0330] "GET /ms-themes.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:27:05 +0330] "GET /wp-includes/assets/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 194.54.144.105 - - [02/Dec/2025:19:27:07 +0330] "GET /style.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:27:08 +0330] "GET /wp-includes/infi.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 194.54.144.105 - - [02/Dec/2025:19:27:09 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 194.54.144.105 - - [02/Dec/2025:19:27:10 +0330] "GET /x.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 194.54.144.105 - - [02/Dec/2025:19:27:11 +0330] "GET /wp-includes/IXR/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 89.187.177.123 - - [02/Dec/2025:19:27:45 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:27:45 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:27:46 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:27:47 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:47 +0330] "GET /wp-includes/ID3 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:47 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 500 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:47 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 89.187.177.123 - - [02/Dec/2025:19:27:47 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:48 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 89.187.177.123 - - [02/Dec/2025:19:27:48 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:49 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:50 +0330] "GET /wp-content/uploads/ao_ccss/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:27:51 +0330] "GET /wp-content/uploads/2021/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:51 +0330] "GET /wp-content/plugins/elementor/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:52 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:27:53 +0330] "GET /upload/image/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:54 +0330] "GET /wordpress/wp-content/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:55 +0330] "GET /wordpress/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 89.187.177.123 - - [02/Dec/2025:19:27:56 +0330] "GET /blog/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 89.187.177.123 - - [02/Dec/2025:19:27:57 +0330] "GET /sites/default/files/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:27:59 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:00 +0330] "GET /admin/editor/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:01 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:02 +0330] "GET /admin/tmp/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:04 +0330] "GET /admin/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:28:05 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:06 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:28:07 +0330] "GET /administrator/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 89.187.177.123 - - [02/Dec/2025:19:28:08 +0330] "GET /ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:10 +0330] "GET /assets/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:11 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:11 +0330] "GET /components/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:13 +0330] "GET /home/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:14 +0330] "GET /include/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:15 +0330] "GET /modules/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 89.187.177.123 - - [02/Dec/2025:19:28:16 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 89.187.177.123 - - [02/Dec/2025:19:28:18 +0330] "GET /mt/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:19 +0330] "GET /site/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:20 +0330] "GET /tmps/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 89.187.177.123 - - [02/Dec/2025:19:28:22 +0330] "GET /wordpress/wp-admin/includes/wp-admin/js/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 89.187.177.123 - - [02/Dec/2025:19:28:23 +0330] "GET /wp-admin/css/colors/light/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:23 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 89.187.177.123 - - [02/Dec/2025:19:28:23 +0330] "GET /wp-admin/css/colors/modern/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:23 +0330] "GET /wp-admin/css/colors/ocean/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:24 +0330] "GET /wp-content/languages/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:24 +0330] "GET /wp-content/uploads/2022/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:24 +0330] "GET /wp-content/uploads/2023/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:24 +0330] "GET /wp-content/uploads/2024/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:24 +0330] "GET /wp-includes/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 89.187.177.123 - - [02/Dec/2025:19:28:26 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:26 +0330] "GET /wp-includes/ID3/wp-includes/IXR/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:27 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:28:27 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:28:27 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 89.187.177.123 - - [02/Dec/2025:19:28:27 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:29 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:29 +0330] "GET /wp-includes/js/plupload/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:29 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:29 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 89.187.177.123 - - [02/Dec/2025:19:28:29 +0330] "GET /cache-wordpress/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:28:30 +0330] "GET /wp-content/ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 89.187.177.123 - - [02/Dec/2025:19:28:32 +0330] "GET /wp-content/plugins/linkpreview/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:33 +0330] "GET /wp-content/plugins/aryabot/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:28:34 +0330] "GET /wp-content/plugins/BrutalShell/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:35 +0330] "GET /wp-content/plugins/cache-wordpress/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 89.187.177.123 - - [02/Dec/2025:19:28:37 +0330] "GET /wp-content/plugins/cakil/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:38 +0330] "GET /wp-content/plugins/cekidot/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:40 +0330] "GET /wp-content/plugins/db/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:41 +0330] "GET /wp-content/plugins/home/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:42 +0330] "GET /wp-content/plugins/limit/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:43 +0330] "GET /wp-content/plugins/owfsmac/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:45 +0330] "GET /wp-content/plugins/prenota/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 89.187.177.123 - - [02/Dec/2025:19:28:46 +0330] "GET /wp-content/plugins/random/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:47 +0330] "GET /wp-content/plugins/ubh/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:48 +0330] "GET /wp-content/plugins/Uwogh-Segs/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 89.187.177.123 - - [02/Dec/2025:19:28:49 +0330] "GET /wp-content/plugins/wp-diambar/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:51 +0330] "GET /wp-content/plugins/wp-freeform/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:28:52 +0330] "GET /wp-content/plugins/wp-hps/sh/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:53 +0330] "GET /wp-content/plugins/wpeazvp/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:28:54 +0330] "GET /wp-content/plugins/zaen/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:55 +0330] "GET /wp-content/uploads/revslider/templates/immersion-photography/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:56 +0330] "GET /patriotic/wp-includes/images/smilies/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:58 +0330] "GET /wp-includes/js/tinymce/plugins/fullscreen/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:58 +0330] "GET /wp-content/plugins/core-stab/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:28:59 +0330] "GET /wp-content/themes/alera/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 89.187.177.123 - - [02/Dec/2025:19:29:00 +0330] "GET /wp-content/themes/rishi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 89.187.177.123 - - [02/Dec/2025:19:29:01 +0330] "GET /wp-content/themes/sketch/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 89.187.177.123 - - [02/Dec/2025:19:29:03 +0330] "GET /wp-content/themes/thuoc-nam/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:29:04 +0330] "GET /wp-content/themes/twentyfive/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:05 +0330] "GET /wp-content/themes/wp-pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:06 +0330] "GET /wp-content/themes/pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:07 +0330] "GET /wp-content/themes/zakra/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:09 +0330] "GET /wp-content/uploads/simple-file-list/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:10 +0330] "GET /admin/upload/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:11 +0330] "GET /wp-admin/css/colors/blue/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:11 +0330] "GET /up/.well-known/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:12 +0330] "GET /wp-content/plugins/apikey/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:14 +0330] "GET /images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:14 +0330] "GET /css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:29:14 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:14 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:14 +0330] "GET /wp-includes/SimplePie/XML/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:29:15 +0330] "GET /wp-content/uploads/wpr-addons/forms/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 89.187.177.123 - - [02/Dec/2025:19:29:17 +0330] "GET /wp-content/plugins/WordPressCore/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 89.187.177.123 - - [02/Dec/2025:19:29:18 +0330] "GET /wordpress/wp-admin/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:19 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:19 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:19 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:19 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:20 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 89.187.177.123 - - [02/Dec/2025:19:29:20 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:20 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:20 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:20 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:20 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:29:21 +0330] "GET /wp-content/plugins/pwnd/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:22 +0330] "GET /about/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:23 +0330] "GET /plugins/jquery.filer/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:24 +0330] "GET /wp-content/plugins/dummyyummy/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 89.187.177.123 - - [02/Dec/2025:19:29:26 +0330] "GET /wp-content/themes/seotheme/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:29:27 +0330] "GET /wp-content/plugins/core/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:28 +0330] "GET /wp-content/plugins/revslider/includes/external/page/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:29:29 +0330] "GET /wp-content/plugins/Cache/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:30 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:30 +0330] "GET /wp-content/plugins/seoplugins/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:29:31 +0330] "GET /fonts/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 89.187.177.123 - - [02/Dec/2025:19:29:32 +0330] "GET /js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:32 +0330] "GET /routes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 89.187.177.123 - - [02/Dec/2025:19:29:33 +0330] "GET /uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:34 +0330] "GET /templates/beez3/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:35 +0330] "GET /wp-content/themes/digital-download/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 89.187.177.123 - - [02/Dec/2025:19:29:37 +0330] "GET /wp-content/plugins/wp-theme-editor/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 89.187.177.123 - - [02/Dec/2025:19:29:38 +0330] "GET /templates/atomic/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:39 +0330] "GET /wp-content/plugins/seoo/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:40 +0330] "GET /wp-includes/js/jcrop/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:40 +0330] "GET /wp-content/plugins/google-seo-rank/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:41 +0330] "GET /wp-content/plugins/erin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:42 +0330] "GET /wp-content/maintenance/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:43 +0330] "GET /wp-content/x/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:44 +0330] "GET /wp-content/plugins/seooyanz/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:29:45 +0330] "GET /wp-content/themes/sky-pro/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:29:46 +0330] "GET /wp-content/plugins/cp-pro/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:29:47 +0330] "GET /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 89.187.177.123 - - [02/Dec/2025:19:29:49 +0330] "GET /wp-content/uploads/typehub/custom/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:50 +0330] "GET /wp-content/plugins/rencontre/inc/photo_import/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 89.187.177.123 - - [02/Dec/2025:19:29:51 +0330] "GET /wp-content/plugins/backup-backup/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:52 +0330] "GET /wp-content/plugins/pwnd-1/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 89.187.177.123 - - [02/Dec/2025:19:29:53 +0330] "GET /.tmb/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 89.187.177.123 - - [02/Dec/2025:19:29:54 +0330] "GET /wp-content/plugins/fix/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 89.187.177.123 - - [02/Dec/2025:19:29:55 +0330] "GET /includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 89.187.177.123 - - [02/Dec/2025:19:29:57 +0330] "GET /themes/pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 43.130.9.111 - - [02/Dec/2025:19:34:53 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 193.29.139.143 - - [02/Dec/2025:20:15:21 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" 185.189.114.116 - - [02/Dec/2025:20:23:26 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:41:02 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:41:09 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:41:15 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:41:22 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:41:29 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:41:36 +0330] "GET /xmlrpc.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:41:40 +0330] "GET /api.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.230.41.104 - - [02/Dec/2025:20:41:55 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:41:55 +0330] "GET /cgi-bin/file.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:42:02 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:42:24 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:42:31 +0330] "GET /new.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:42:38 +0330] "GET /NewFile.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:42:45 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 36.41.75.167 - - [02/Dec/2025:20:41:30 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:41:48 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:42:10 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:42:17 +0330] "GET /cong.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:42:52 +0330] "GET /file5.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:42:59 +0330] "GET /gel4y.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:43:06 +0330] "GET /info.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:43:13 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:43:21 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:43:28 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:43:35 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 105.155.161.47 - - [02/Dec/2025:20:43:51 +0330] "GET //rest.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:44:02 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:44:17 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:44:17 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:44:17 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:20:44:20 +0330] "GET //login.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:44:29 +0330] "GET //Jada.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:44:37 +0330] "GET //zone.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:44:46 +0330] "GET //zonexx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:44:54 +0330] "GET //403webshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:45:10 +0330] "GET //O-Simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:45:10 +0330] "GET /wp-content/et-cache/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:20:45:33 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:45:40 +0330] "GET //berax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:45:43 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:20:43:40 +0330] "GET //simi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:43:48 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:20:44:02 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:44:09 +0330] "GET //sx21_1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:44:31 +0330] "GET /wp-admin/js/wp-login.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:44:44 +0330] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:44:56 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:20:45:02 +0330] "GET //MuPlugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:45:03 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:45:17 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:45:17 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 105.155.161.47 - - [02/Dec/2025:20:45:18 +0330] "GET //ObeQY2t7P.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:45:24 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:20:45:25 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:45:31 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:45:36 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:45:37 +0330] "GET /wp-good.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 105.155.161.47 - - [02/Dec/2025:20:45:59 +0330] "GET //click.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:45:43 +0330] "GET /wp-includes/SimplePie/autoload_classmap.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 105.155.161.47 - - [02/Dec/2025:20:45:50 +0330] "GET //ckmail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:45:51 +0330] "GET /wp-includes/SimplePie/chosen.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:45:57 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:46:03 +0330] "GET /wp-includes/css/autoload_classmap.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 105.155.161.47 - - [02/Dec/2025:20:46:06 +0330] "GET //csv.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:46:10 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.230.41.104 - - [02/Dec/2025:20:46:32 +0330] "GET /wp-includes/style-engine/wp-conflg.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:20:46:46 +0330] "GET //ex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:46:53 +0330] "GET //execlude.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:47:00 +0330] "GET //f8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:47:14 +0330] "GET //fix.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:47:26 +0330] "GET //inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:47:39 +0330] "GET //mah.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:47:46 +0330] "GET //asmtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:00 +0330] "GET //about.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:08 +0330] "GET //chosen.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:21 +0330] "GET //shop.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:28 +0330] "GET //r.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:46:13 +0330] "GET //database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:46:15 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 403 787 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:46:16 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:46:16 +0330] "GET /wp-includes/rest-api/search/index.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:46:20 +0330] "GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 105.155.161.47 - - [02/Dec/2025:20:46:20 +0330] "GET //database.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:46:26 +0330] "GET /wp-includes/style-engine/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 105.155.161.47 - - [02/Dec/2025:20:46:26 +0330] "GET //db.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:46:33 +0330] "GET //defaults.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:46:38 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.230.41.104 - - [02/Dec/2025:20:46:38 +0330] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 105.155.161.47 - - [02/Dec/2025:20:46:39 +0330] "GET //documentroot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 4.230.41.104 - - [02/Dec/2025:20:46:43 +0330] "GET /wp.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 105.155.161.47 - - [02/Dec/2025:20:47:06 +0330] "GET //fix.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:47:20 +0330] "GET //goods.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:47:33 +0330] "GET //item.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:47:54 +0330] "GET //malro.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:14 +0330] "GET //content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:48 +0330] "GET //b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:34 +0330] "GET //y.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:42 +0330] "GET //a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:48:55 +0330] "GET //c.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:15 +0330] "GET //aa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:22 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:35 +0330] "GET //core.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:57 +0330] "GET //lf_utchiha.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:05 +0330] "GET //ninjasec.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:19 +0330] "GET //alfanew.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:40 +0330] "GET //style.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:47 +0330] "GET //xmlrpc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:51:06 +0330] "GET //simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:51:27 +0330] "GET //xleet.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:51:34 +0330] "GET //rain.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:51:41 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:51:57 +0330] "GET //contents.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:52:05 +0330] "GET //copy.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:52:13 +0330] "GET //fw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:52:20 +0330] "GET //ae.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:52:27 +0330] "GET //glppziux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:52:41 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:52:53 +0330] "GET //1337.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:02 +0330] "GET //e.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:09 +0330] "GET //zz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:29 +0330] "GET //wordpress.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:42 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:49:49 +0330] "GET //zossipei.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:13 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:27 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:33 +0330] "GET //utchiha_offer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:52 +0330] "GET //shell-script.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:50:59 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:51:13 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:51:20 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:51:47 +0330] "GET //dnvokikk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:52:33 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:52:47 +0330] "GET //srx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:06 +0330] "GET //doc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:00 +0330] "GET //ups.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:13 +0330] "GET //xx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:20 +0330] "GET //leaf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:27 +0330] "GET //leafmailer2.8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:34 +0330] "GET //lf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:40 +0330] "GET //alex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:47 +0330] "GET //new.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:21 +0330] "GET //1index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:28 +0330] "GET //3index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:47 +0330] "GET //alfa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:00 +0330] "GET //bb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:13 +0330] "GET //Lux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:26 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:45 +0330] "GET //uplo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:53 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:00 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:07 +0330] "GET //wp-content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:15 +0330] "GET //wp-upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:26 +0330] "GET //404.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:39 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:45 +0330] "GET //smtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:52 +0330] "GET //azerty.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:04 +0330] "GET //WSO.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:53:53 +0330] "GET //mailer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:02 +0330] "GET //marijuana.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:08 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:15 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:35 +0330] "GET //wikindex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:41 +0330] "GET //wso1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:54:54 +0330] "GET //priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:07 +0330] "GET //m.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:19 +0330] "GET //haxor.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:32 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:55:38 +0330] "GET //send.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:22 +0330] "GET //wp-mail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:32 +0330] "GET //asad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:56:58 +0330] "GET //dell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:30 +0330] "GET //sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:37 +0330] "GET //mysql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:43 +0330] "GET //madspot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:55 +0330] "GET //cpbt.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:10 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:17 +0330] "GET //r99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:57 +0330] "GET //d0main.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:15 +0330] "GET //Cgishell.pl HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:10 +0330] "GET //dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:17 +0330] "GET //cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:23 +0330] "GET //cpn.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:57:49 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:02 +0330] "GET //sYm.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:24 +0330] "GET //lol.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:31 +0330] "GET //jo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:37 +0330] "GET //wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:44 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:58:50 +0330] "GET //shellz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:04 +0330] "GET //d0mains.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:10 +0330] "GET /users.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:41 +0330] "GET //Sh3ll.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:47 +0330] "GET //dz0.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:53 +0330] "GET //dam.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:07 +0330] "GET //dom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:14 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:21 +0330] "GET //r00t.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:34 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:41 +0330] "GET //1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:54 +0330] "GET /madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:59 +0330] "GET //Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:21 +0330] "GET //killer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:28 +0330] "GET //changeall.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:20:59:34 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:00 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:00:28 +0330] "GET //c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 152.42.181.252 - - [02/Dec/2025:21:00:32 +0330] "GET /sftp-config.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 152.42.181.252 - - [02/Dec/2025:21:00:37 +0330] "GET /.vscode/sftp.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 105.155.161.47 - - [02/Dec/2025:21:00:48 +0330] "GET //wp.zip HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:05 +0330] "GET //c22.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:12 +0330] "GET //c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:21 +0330] "GET //Cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:31 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:49 +0330] "GET /d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:54 +0330] "GET /tmp/d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:25 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:30 +0330] "GET /sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:38 +0330] "GET /admin1/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:47 +0330] "GET /images/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:52 +0330] "GET //r57.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:59 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:12 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:32 +0330] "GET /gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:38 +0330] "GET //madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:45 +0330] "GET /L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:01:59 +0330] "GET /tmp/L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:04 +0330] "GET /admin1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:11 +0330] "GET /upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:16 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:21 +0330] "GET /admin2.asp HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:34 +0330] "GET /sysadmins/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:02:43 +0330] "GET /administration/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:06 +0330] "GET //sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:19 +0330] "GET //sa2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:25 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:36 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:41 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:49 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:53 +0330] "GET /shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:03 +0330] "GET /t00.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:08 +0330] "GET /dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:19 +0330] "GET /asp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:23 +0330] "GET /whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:27 +0330] "GET /d0maine.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:40 +0330] "GET /dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:03:58 +0330] "GET /amad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:14 +0330] "GET /Black.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:31 +0330] "GET /tmp/sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:35 +0330] "GET /tmp/dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:44 +0330] "GET /Symlink.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:48 +0330] "GET /wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:56 +0330] "GET /images/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:05 +0330] "GET /c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:14 +0330] "GET /Server.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:18 +0330] "GET /wp-admin/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:27 +0330] "GET /tmp/priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:32 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:45 +0330] "GET /w.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:50 +0330] "GET /1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:04 +0330] "GET /4.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:09 +0330] "GET /5.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:21 +0330] "GET /amhlzdhk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:27 +0330] "GET /balance.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:37 +0330] "GET /database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:47 +0330] "GET /index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:54 +0330] "GET /inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:58 +0330] "GET /nf_tracking.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:04:52 +0330] "GET /sysadmin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:01 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:09 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:36 +0330] "GET /admins.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:41 +0330] "GET /a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:55 +0330] "GET /2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:05:59 +0330] "GET /3.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:15 +0330] "GET /6.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:32 +0330] "GET /curl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:06:42 +0330] "GET /hyivatpf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:07 +0330] "GET /slax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:16 +0330] "GET /todo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:21 +0330] "GET /ttcecnmc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:30 +0330] "GET /unzipper.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:34 +0330] "GET /unZIPpeRqyr.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:39 +0330] "GET /ut.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:52 +0330] "GET /webhook.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:08:09 +0330] "GET /wqjtejxi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:08:20 +0330] "GET /zvpqaqfb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:08:32 +0330] "GET //shadow.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:08:38 +0330] "GET //plugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 172.86.68.246 - - [02/Dec/2025:21:09:16 +0330] "GET /userfuns.php HTTP/1.1" 403 6888 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.155.161.47 - - [02/Dec/2025:21:07:03 +0330] "GET /qkyplyur.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:12 +0330] "GET /tesTlme.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:25 +0330] "GET /txfpcuhw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:43 +0330] "GET /utchiha2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:48 +0330] "GET /uuhoxcyb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:07:57 +0330] "GET /wp-atom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:08:05 +0330] "GET /wp-pano.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:08:15 +0330] "GET /wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 105.155.161.47 - - [02/Dec/2025:21:08:25 +0330] "GET //xl2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 172.86.68.246 - - [02/Dec/2025:21:09:17 +0330] "GET /postnews.php HTTP/1.1" 403 6888 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:22:14:33 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:22:14:33 +0330] "GET / HTTP/1.1" 403 17364 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:22:14:34 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:22:14:33 +0330] "POST /wp-plain.php HTTP/1.1" 404 101828 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:22:14:37 +0330] "GET /sireofnq.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:22:14:33 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 157.66.56.12 - - [02/Dec/2025:22:48:12 +0330] "GET /sftp-config.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 157.66.56.12 - - [02/Dec/2025:22:48:17 +0330] "GET /.vscode/sftp.json HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 151.234.249.43 - - [02/Dec/2025:22:51:42 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 4.241.208.113 - - [02/Dec/2025:23:15:04 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:23:15:04 +0330] "GET / HTTP/1.1" 403 17364 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:23:15:04 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:23:15:05 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [02/Dec/2025:23:15:04 +0330] "POST /wp-plain.php HTTP/1.1" 404 101719 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.214.174.196 - - [02/Dec/2025:23:15:07 +0330] "POST /wp-cron.php?doing_wp_cron=1764704707.7448959350585937500000 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 57.129.25.24 - - [03/Dec/2025:00:12:30 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_6_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.6 Mobile/15E148 Safari/604.1" 5.133.192.184 - - [03/Dec/2025:01:06:32 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Agency/93.8.2357.5" 5.133.192.200 - - [03/Dec/2025:01:06:36 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Agency/93.8.2357.5" 123.160.223.73 - - [03/Dec/2025:01:43:35 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 123.160.223.72 - - [03/Dec/2025:01:43:24 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" 18.97.9.168 - - [03/Dec/2025:02:33:59 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 107.175.205.148 - - [03/Dec/2025:02:33:38 +0330] "GET / HTTP/1.1" 301 20 "https://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:114.0) Gecko/20100101 Firefox/114.0" 107.175.205.148 - - [03/Dec/2025:02:33:50 +0330] "GET /sevices/ HTTP/1.1" 301 20 "https://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:114.0) Gecko/20100101 Firefox/114.0" 49.51.72.76 - - [03/Dec/2025:02:43:39 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:47:55 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:48:07 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:48:31 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:48:31 +0330] "GET /cgi-bin/file.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:48:57 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:49:04 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:49:18 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:49:25 +0330] "GET /file5.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:49:30 +0330] "GET /gel4y.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:49:58 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:50:05 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:50:24 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:50:38 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 131.186.47.110 - - [03/Dec/2025:02:51:47 +0330] "GET / HTTP/1.1" 301 20 "-" "Python/3.14 aiohttp/3.13.2" 49.7.227.204 - - [03/Dec/2025:02:45:24 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:47:49 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:48:01 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:48:14 +0330] "GET /xmlrpc.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:48:18 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:48:24 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:48:38 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:48:44 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:48:50 +0330] "GET /cong.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:49:11 +0330] "GET /NewFile.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.218.11.183 - - [03/Dec/2025:02:49:37 +0330] "GET /info.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:49:43 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:49:50 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:50:11 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.218.11.183 - - [03/Dec/2025:02:50:55 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:50:55 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.218.11.183 - - [03/Dec/2025:02:51:01 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 43.157.148.38 - - [03/Dec/2025:04:05:35 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 91.92.242.74 - - [03/Dec/2025:04:40:25 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:57.0) Gecko/20100101 Firefox/57.0" 216.24.210.62 - - [03/Dec/2025:05:31:26 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/117.0" 98.178.72.21 - - [03/Dec/2025:05:46:14 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 98.178.72.21 - - [03/Dec/2025:05:46:23 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 98.178.72.21 - - [03/Dec/2025:05:46:42 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 98.178.72.21 - - [03/Dec/2025:05:46:33 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 47.79.216.127 - - [03/Dec/2025:06:30:13 +0330] "GET /?trk=public_post-text HTTP/1.1" 301 20 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 134.122.8.73 - - [03/Dec/2025:07:19:03 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 45.149.173.209 - - [03/Dec/2025:07:22:16 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 141.98.11.169 - - [03/Dec/2025:07:30:15 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15" 18.97.14.85 - - [03/Dec/2025:07:42:06 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 4.241.192.251 - - [03/Dec/2025:08:14:47 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:14:54 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:15:01 +0330] "GET /xmlrpc.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:15:06 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:15:14 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:15:31 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:15:55 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:16:11 +0330] "GET /NewFile.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:16:36 +0330] "GET /gel4y.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 185.39.19.48 - - [03/Dec/2025:08:16:52 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 4.241.192.251 - - [03/Dec/2025:08:16:52 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:17:00 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:17:37 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:14:31 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:14:39 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:15:22 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:08:15:22 +0330] "GET /cgi-bin/file.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:15:39 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:15:47 +0330] "GET /cong.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:16:03 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:16:19 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:16:28 +0330] "GET /file5.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:16:44 +0330] "GET /info.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:17:09 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:17:17 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:17:24 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:08:17:51 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 182.44.9.147 - - [03/Dec/2025:09:00:49 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 65.109.49.32 - - [03/Dec/2025:09:29:51 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 143.244.185.85 - - [03/Dec/2025:09:42:08 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 18.97.9.174 - - [03/Dec/2025:09:45:21 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 43.165.69.68 - - [03/Dec/2025:10:45:35 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 146.70.186.172 - - [03/Dec/2025:10:59:33 +0330] "GET /manager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.172 - - [03/Dec/2025:10:59:34 +0330] "GET /bless.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 146.70.186.172 - - [03/Dec/2025:10:59:35 +0330] "GET /O-Simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:36 +0330] "GET /lock360.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:37 +0330] "GET /zwso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:38 +0330] "GET /chosen.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:39 +0330] "GET /about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:40 +0330] "GET /admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:42 +0330] "GET /.well-known/login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:10:59:43 +0330] "GET /mah.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 146.70.186.172 - - [03/Dec/2025:10:59:44 +0330] "GET /.wp/wso.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:10:59:45 +0330] "GET /core.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:46 +0330] "GET /robots.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:47 +0330] "GET /inputs.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:10:59:48 +0330] "GET /mini.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 146.70.186.172 - - [03/Dec/2025:10:59:49 +0330] "GET /goods.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.172 - - [03/Dec/2025:10:59:50 +0330] "GET /file5.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:10:59:51 +0330] "GET /ahax.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 146.70.186.172 - - [03/Dec/2025:10:59:53 +0330] "GET /f35.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 146.70.186.172 - - [03/Dec/2025:10:59:54 +0330] "GET /simple.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.172 - - [03/Dec/2025:10:59:55 +0330] "GET /update/f35.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 146.70.186.172 - - [03/Dec/2025:10:59:57 +0330] "GET /wp-content/hello.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:10:59:58 +0330] "GET /wp-admin/maint/bootstrap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.172 - - [03/Dec/2025:10:59:59 +0330] "GET /themes/zMousse/otuz1.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:00 +0330] "GET /wp-content/edit-wolf.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.172 - - [03/Dec/2025:11:00:02 +0330] "GET /wp-content/plugins/ubh/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:03 +0330] "GET /wp-admin/images/bootstrap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:05 +0330] "GET /images/upload.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:06 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.172 - - [03/Dec/2025:11:00:07 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:09 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:10 +0330] "GET /admin/uploads/bn_1_1754420677.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:11 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:12 +0330] "GET /wp-content/plugins/pwnd/pwnd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:13 +0330] "GET /wp-content/plugins/pwnd-1/pwnd.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 146.70.186.172 - - [03/Dec/2025:11:00:15 +0330] "GET /wp-admin/css/colors/midnight/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:16 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/kill.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 146.70.186.172 - - [03/Dec/2025:11:00:17 +0330] "GET /wp-includes/style-engine/worksec.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.172 - - [03/Dec/2025:11:00:18 +0330] "GET /wp-admin/images/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:19 +0330] "GET /wp-content/plugins/core-plugin/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 146.70.186.172 - - [03/Dec/2025:11:00:20 +0330] "GET /wp-content/plugins/envato-css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:21 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:22 +0330] "GET /uploads/94056-upload.phtml HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:23 +0330] "GET /index/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.172 - - [03/Dec/2025:11:00:24 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.172 - - [03/Dec/2025:11:00:26 +0330] "GET /js/bas.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:27 +0330] "GET /.well-known/pki-validation/moon.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 146.70.186.172 - - [03/Dec/2025:11:00:27 +0330] "GET /file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:28 +0330] "GET /wp-includes/js/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:29 +0330] "GET /wp-content/upgrade/item.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.172 - - [03/Dec/2025:11:00:31 +0330] "GET /buy.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:32 +0330] "GET /wp-content/languages/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:33 +0330] "GET /wp-content/themes/classwithtostring.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 146.70.186.172 - - [03/Dec/2025:11:00:34 +0330] "GET /wp-content/plugins/elementor/wp-wjvngrh.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 146.70.186.172 - - [03/Dec/2025:11:00:35 +0330] "GET /wp-includes/IXR/fix.php7 HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:36 +0330] "GET /wp-includes/widgets/dyqvcfqv.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:38 +0330] "GET /admin/function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:39 +0330] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:40 +0330] "GET /wp-includes/js/crop/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:41 +0330] "GET /wp-includes/PHPMailer/wp-conflg.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:42 +0330] "GET /wp-includes/PHPMailer/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.172 - - [03/Dec/2025:11:00:43 +0330] "GET /wp-includes/widgets/wp-login.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.172 - - [03/Dec/2025:11:00:44 +0330] "GET /files/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:45 +0330] "GET /wp-includes/PHPMailer/options.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:46 +0330] "GET /inc.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 146.70.186.172 - - [03/Dec/2025:11:00:48 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 146.70.186.172 - - [03/Dec/2025:11:00:48 +0330] "GET /filemanager.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 146.70.186.172 - - [03/Dec/2025:11:00:49 +0330] "GET /cgi-bin/bypass.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:50 +0330] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 796 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:50 +0330] "GET /wp-includes/IXR/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:52 +0330] "GET /wp-admin/js/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:53 +0330] "GET /wp-includes/js/jquery/jquery.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 146.70.186.172 - - [03/Dec/2025:11:00:54 +0330] "GET /function.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:55 +0330] "GET /wp-includes/block-supports/autoload_classmap.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:56 +0330] "GET /wp-signup.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:00:58 +0330] "GET /wp-admin/network/network.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 146.70.186.172 - - [03/Dec/2025:11:00:59 +0330] "GET /admin/upload/css.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:01:00 +0330] "GET /wp-blog.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.172 - - [03/Dec/2025:11:01:01 +0330] "GET /wp-admin/file.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:01:02 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:15 +0330] "GET /wp-includes/css/dist/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:15 +0330] "GET /wp-includes/js/dist/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:15 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:16 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:16 +0330] "GET /wp-content/plugins/erinyani/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 146.70.186.142 - - [03/Dec/2025:11:01:17 +0330] "GET /wp-includes/l10n/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:17 +0330] "GET /wp-content/uploads/2023/11/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:17 +0330] "GET /wp-includes/sodium_compat/lib/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 146.70.186.142 - - [03/Dec/2025:11:01:17 +0330] "GET /wp-includes/blocks/file/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:18 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:18 +0330] "GET /wp-includes/block-bindings/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:18 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:18 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:18 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:20 +0330] "GET /wp-admin/css/colors/sunrise/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.142 - - [03/Dec/2025:11:01:20 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:20 +0330] "GET /wp-content/plugins/ioxi/ioxi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:21 +0330] "GET /wp-includes/id3/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:22 +0330] "GET /wp-includes/blocks/query/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:22 +0330] "GET /wp-includes/js/tinymce/langs/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:23 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 146.70.186.142 - - [03/Dec/2025:11:01:23 +0330] "GET /wp-includes/blocks/group/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 146.70.186.142 - - [03/Dec/2025:11:01:23 +0330] "GET /blog/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 146.70.186.142 - - [03/Dec/2025:11:01:24 +0330] "GET /wp-content/themes/twentytwentyfour/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:25 +0330] "GET /wp-includes/interactivity-api/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 146.70.186.142 - - [03/Dec/2025:11:01:25 +0330] "GET /wp-includes/wp-class.php/wp-content/themes/travelscape/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:26 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:27 +0330] "GET /wp-admin/js/dist/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:28 +0330] "GET /assets/css/dist/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:29 +0330] "GET /wp-includes/js/jquery/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:29 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:29 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 146.70.186.142 - - [03/Dec/2025:11:01:29 +0330] "GET /wp-content/plugins/wp-file-manager/admin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:31 +0330] "GET /wp-admin/js/widget/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:32 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:33 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:33 +0330] "GET /wp-content/themes/tflow/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:34 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:35 +0330] "GET /wordpress/wp-admin/includes HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:37 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:37 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:38 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 146.70.186.142 - - [03/Dec/2025:11:01:38 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:39 +0330] "GET /wp-includes/ID3 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 146.70.186.142 - - [03/Dec/2025:11:01:39 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 500 2 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:39 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:39 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:39 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:40 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 146.70.186.142 - - [03/Dec/2025:11:01:41 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:42 +0330] "GET /wp-content/uploads/ao_ccss/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:43 +0330] "GET /wp-content/uploads/2021/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:43 +0330] "GET /wp-content/plugins/elementor/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:44 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:45 +0330] "GET /upload/image/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 146.70.186.142 - - [03/Dec/2025:11:01:46 +0330] "GET /wordpress/wp-content/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:47 +0330] "GET /wordpress/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:48 +0330] "GET /blog/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:01:50 +0330] "GET /sites/default/files/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:51 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 146.70.186.142 - - [03/Dec/2025:11:01:52 +0330] "GET /admin/editor/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:01:53 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:55 +0330] "GET /admin/tmp/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 146.70.186.142 - - [03/Dec/2025:11:01:56 +0330] "GET /admin/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 146.70.186.142 - - [03/Dec/2025:11:01:57 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:01:58 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 146.70.186.142 - - [03/Dec/2025:11:01:59 +0330] "GET /administrator/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:01 +0330] "GET /ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:02:02 +0330] "GET /assets/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:03 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:03 +0330] "GET /components/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 146.70.186.142 - - [03/Dec/2025:11:02:04 +0330] "GET /home/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.142 - - [03/Dec/2025:11:02:05 +0330] "GET /include/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:06 +0330] "GET /modules/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:08 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:09 +0330] "GET /mt/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:10 +0330] "GET /site/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.142 - - [03/Dec/2025:11:02:11 +0330] "GET /tmps/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:02:12 +0330] "GET /wordpress/wp-admin/includes/wp-admin/js/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:13 +0330] "GET /wp-admin/css/colors/light/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 146.70.186.142 - - [03/Dec/2025:11:02:13 +0330] "GET /wp-admin/css/colors/midnight/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 146.70.186.142 - - [03/Dec/2025:11:02:14 +0330] "GET /wp-admin/css/colors/modern/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:02:14 +0330] "GET /wp-admin/css/colors/ocean/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:14 +0330] "GET /wp-content/languages/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:14 +0330] "GET /wp-content/uploads/2022/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:14 +0330] "GET /wp-content/uploads/2023/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:14 +0330] "GET /wp-content/uploads/2024/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:15 +0330] "GET /wp-includes/wp-includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:02:16 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 146.70.186.142 - - [03/Dec/2025:11:02:16 +0330] "GET /wp-includes/ID3/wp-includes/IXR/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:02:17 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:17 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:18 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:18 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:19 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 146.70.186.142 - - [03/Dec/2025:11:02:19 +0330] "GET /wp-includes/js/plupload/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:19 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:02:20 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:02:20 +0330] "GET /cache-wordpress/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 146.70.186.142 - - [03/Dec/2025:11:02:21 +0330] "GET /wp-content/ALFA_DATA/alfacgiapi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 146.70.186.142 - - [03/Dec/2025:11:02:22 +0330] "GET /wp-content/plugins/linkpreview/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.142 - - [03/Dec/2025:11:02:23 +0330] "GET /wp-content/plugins/aryabot/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 146.70.186.142 - - [03/Dec/2025:11:02:24 +0330] "GET /wp-content/plugins/BrutalShell/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 146.70.186.142 - - [03/Dec/2025:11:02:25 +0330] "GET /wp-content/plugins/cache-wordpress/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:27 +0330] "GET /wp-content/plugins/cakil/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:28 +0330] "GET /wp-content/plugins/cekidot/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:29 +0330] "GET /wp-content/plugins/db/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:30 +0330] "GET /wp-content/plugins/home/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.142 - - [03/Dec/2025:11:02:31 +0330] "GET /wp-content/plugins/limit/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:32 +0330] "GET /wp-content/plugins/owfsmac/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 146.70.186.142 - - [03/Dec/2025:11:02:33 +0330] "GET /wp-content/plugins/prenota/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:02:34 +0330] "GET /wp-content/plugins/random/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:35 +0330] "GET /wp-content/plugins/ubh/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 146.70.186.142 - - [03/Dec/2025:11:02:36 +0330] "GET /wp-content/plugins/Uwogh-Segs/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.142 - - [03/Dec/2025:11:02:37 +0330] "GET /wp-content/plugins/wp-diambar/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.142 - - [03/Dec/2025:11:02:39 +0330] "GET /wp-content/plugins/wp-freeform/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:02:40 +0330] "GET /wp-content/plugins/wp-hps/sh/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 146.70.186.142 - - [03/Dec/2025:11:02:41 +0330] "GET /wp-content/plugins/wpeazvp/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:42 +0330] "GET /wp-content/plugins/zaen/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:43 +0330] "GET /wp-content/uploads/revslider/templates/immersion-photography/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:44 +0330] "GET /patriotic/wp-includes/images/smilies/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 146.70.186.142 - - [03/Dec/2025:11:02:45 +0330] "GET /wp-includes/js/tinymce/plugins/fullscreen/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 146.70.186.142 - - [03/Dec/2025:11:02:45 +0330] "GET /wp-content/plugins/core-stab/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:46 +0330] "GET /wp-content/themes/alera/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:02:47 +0330] "GET /wp-content/themes/rishi/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 146.70.186.142 - - [03/Dec/2025:11:02:48 +0330] "GET /wp-content/themes/sketch/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:02:49 +0330] "GET /wp-content/themes/thuoc-nam/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:02:51 +0330] "GET /wp-content/themes/twentyfive/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 146.70.186.142 - - [03/Dec/2025:11:02:52 +0330] "GET /wp-content/themes/wp-pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:53 +0330] "GET /wp-content/themes/pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 146.70.186.142 - - [03/Dec/2025:11:02:54 +0330] "GET /wp-content/themes/zakra/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:02:55 +0330] "GET /wp-content/uploads/simple-file-list/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 146.70.186.142 - - [03/Dec/2025:11:02:56 +0330] "GET /admin/upload/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 146.70.186.142 - - [03/Dec/2025:11:02:57 +0330] "GET /wp-admin/css/colors/blue/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:02:58 +0330] "GET /up/.well-known/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:02:59 +0330] "GET /wp-content/plugins/apikey/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:00 +0330] "GET /images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:03:00 +0330] "GET /css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:03:01 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:01 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:01 +0330] "GET /wp-includes/SimplePie/XML/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:02 +0330] "GET /wp-content/uploads/wpr-addons/forms/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:03 +0330] "GET /wp-content/plugins/WordPressCore/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.142 - - [03/Dec/2025:11:03:04 +0330] "GET /wordpress/wp-admin/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.142 - - [03/Dec/2025:11:03:06 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.142 - - [03/Dec/2025:11:03:06 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:06 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.142 - - [03/Dec/2025:11:03:06 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:06 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:06 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:07 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:07 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:07 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:07 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:07 +0330] "GET /wp-content/plugins/pwnd/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:09 +0330] "GET /about/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:10 +0330] "GET /plugins/jquery.filer/uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 146.70.186.142 - - [03/Dec/2025:11:03:11 +0330] "GET /wp-content/plugins/dummyyummy/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:03:12 +0330] "GET /wp-content/themes/seotheme/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:13 +0330] "GET /wp-content/plugins/core/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.142 - - [03/Dec/2025:11:03:14 +0330] "GET /wp-content/plugins/revslider/includes/external/page/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:15 +0330] "GET /wp-content/plugins/Cache/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:16 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 146.70.186.142 - - [03/Dec/2025:11:03:17 +0330] "GET /wp-content/plugins/seoplugins/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:18 +0330] "GET /fonts/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:18 +0330] "GET /js/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:18 +0330] "GET /routes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:19 +0330] "GET /uploads/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:03:21 +0330] "GET /templates/beez3/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:22 +0330] "GET /wp-content/themes/digital-download/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 146.70.186.142 - - [03/Dec/2025:11:03:23 +0330] "GET /wp-content/plugins/wp-theme-editor/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 146.70.186.142 - - [03/Dec/2025:11:03:24 +0330] "GET /templates/atomic/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:25 +0330] "GET /wp-content/plugins/seoo/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:26 +0330] "GET /wp-includes/js/jcrop/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 146.70.186.142 - - [03/Dec/2025:11:03:26 +0330] "GET /wp-content/plugins/google-seo-rank/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.172 - - [03/Dec/2025:11:01:04 +0330] "GET /wp-includes/blocks/table/int/tmpl/index.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:03:28 +0330] "GET /wp-content/plugins/erin/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:29 +0330] "GET /wp-content/maintenance/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 146.70.186.142 - - [03/Dec/2025:11:03:29 +0330] "GET /wp-content/x/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 146.70.186.142 - - [03/Dec/2025:11:03:30 +0330] "GET /wp-content/plugins/seooyanz/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 146.70.186.142 - - [03/Dec/2025:11:03:31 +0330] "GET /wp-content/themes/sky-pro/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:32 +0330] "GET /wp-content/plugins/cp-pro/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:33 +0330] "GET /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:03:34 +0330] "GET /wp-content/uploads/typehub/custom/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 146.70.186.142 - - [03/Dec/2025:11:03:35 +0330] "GET /wp-content/plugins/rencontre/inc/photo_import/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 146.70.186.142 - - [03/Dec/2025:11:03:36 +0330] "GET /wp-content/plugins/backup-backup/includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 146.70.186.142 - - [03/Dec/2025:11:03:37 +0330] "GET /wp-content/plugins/pwnd-1/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:38 +0330] "GET /.tmb/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:39 +0330] "GET /wp-content/plugins/fix/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:40 +0330] "GET /includes/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 146.70.186.142 - - [03/Dec/2025:11:03:41 +0330] "GET /themes/pridmag/ HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 167.71.244.226 - - [03/Dec/2025:11:38:13 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 18.97.9.168 - - [03/Dec/2025:11:48:16 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 4.241.208.113 - - [03/Dec/2025:11:58:44 +0330] "POST /wp-plain.php HTTP/1.1" 404 101828 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [03/Dec/2025:11:58:49 +0330] "GET /xybciyjk.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 49.51.39.209 - - [03/Dec/2025:11:54:13 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 4.241.208.113 - - [03/Dec/2025:11:58:44 +0330] "GET / HTTP/1.1" 403 17362 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [03/Dec/2025:11:58:45 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 167.71.188.71 - - [03/Dec/2025:12:06:15 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 114.119.158.157 - - [03/Dec/2025:12:25:05 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible;PetalBot;+https://webmaster.petalsearch.com/site/petalbot)" 4.241.192.251 - - [03/Dec/2025:13:37:26 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 185.39.19.48 - - [03/Dec/2025:13:37:41 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:37:54 +0330] "GET /xmlrpc.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:37:58 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:38:06 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:38:21 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:38:29 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:38:45 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:38:53 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [03/Dec/2025:13:39:01 +0330] "GET /NewFile.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:39:57 +0330] "GET /themes.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:37:35 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:37:40 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:37:47 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:38:14 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:38:14 +0330] "GET /cgi-bin/file.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:38:37 +0330] "GET /cong.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:39:09 +0330] "GET /file.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:39:16 +0330] "GET /file5.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:39:24 +0330] "GET /gel4y.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:39:32 +0330] "GET /info.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:39:40 +0330] "GET /ioxi-o.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:39:48 +0330] "GET /radio.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:40:05 +0330] "GET /bolt.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:40:14 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:40:29 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:40:44 +0330] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:40:58 +0330] "GET /wp-admin/js/ HTTP/1.1" 403 787 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:40:58 +0330] "GET /wp-admin/js/widgets/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:40:59 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:41:26 +0330] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:41:39 +0330] "GET /wp-content/1.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:41:46 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:42:02 +0330] "GET /wp-content/index.php HTTP/1.1" 500 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:03 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:10 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:42:29 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:29 +0330] "GET /wp-includes/SimplePie/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:34 +0330] "GET /wp-includes/SimplePie/chosen.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:40 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:45 +0330] "GET /wp-includes/css/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:42:50 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:43:16 +0330] "GET /wp-includes/style-engine/wp-conflg.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:43:30 +0330] "GET /wp.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:41:12 +0330] "GET /wp-admin/js/wp-login.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 4.241.192.251 - - [03/Dec/2025:13:41:54 +0330] "GET /wp-content/et-cache/ HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:17 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:42:22 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:22 +0330] "GET /wp-good.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:57 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 403 787 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:57 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:42:57 +0330] "GET /wp-includes/rest-api/search/index.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:43:02 +0330] "GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:43:09 +0330] "GET /wp-includes/style-engine/autoload_classmap.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:13:43:23 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:13:43:23 +0330] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 18.97.14.82 - - [03/Dec/2025:14:07:00 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 156.146.33.74 - - [03/Dec/2025:14:27:42 +0330] "GET /uploads/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:46 +0330] "GET /upload/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:49 +0330] "GET /admin/uploads/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:52 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:56 +0330] "GET /admin/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:59 +0330] "GET /images/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:59 +0330] "GET /assets/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:03 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:07 +0330] "GET /upload/image/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:10 +0330] "GET /assets/images/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:14 +0330] "GET /Public/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:17 +0330] "GET /vendor/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:20 +0330] "GET /local/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:24 +0330] "GET /modules/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:27 +0330] "GET /Site/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:30 +0330] "GET /system/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:34 +0330] "GET /template/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:37 +0330] "GET /shop/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:41 +0330] "GET /files/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:45 +0330] "GET /admin/editor/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:48 +0330] "GET /include/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:52 +0330] "GET /Assets/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:55 +0330] "GET /images/stories/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:28:59 +0330] "GET /plugins/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:03 +0330] "GET /php/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:06 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:07 +0330] "GET /wp-content/themes/twentytwenty/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:07 +0330] "GET /wp-content/cache/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:10 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:10 +0330] "GET /wp-content/plugins/akismet/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:10 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:10 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:11 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:11 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:11 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:11 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:11 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:11 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:11 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:15 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:15 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:15 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:15 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:15 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:15 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:15 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:15 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:16 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:19 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:23 +0330] "GET /sites/default/files/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:26 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:30 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:33 +0330] "GET /components/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:37 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:40 +0330] "GET /wp-content/plugins/classic-editor/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:44 +0330] "GET /wp-content/fonts/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:47 +0330] "GET /wp-content/plugins/contact-form-7/admin/js/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:50 +0330] "GET /wp-content/plugins/contact-form-7/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:54 +0330] "GET /wordpress/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:57 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:57 +0330] "GET /wp-content/plugins/wordpress-seo/js/dist/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:57 +0330] "GET /wp-content/plugins/wordpress-seo/ HTTP/1.1" 500 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:58 +0330] "GET /js/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:29:58 +0330] "GET /wp-content/plugins/woocommerce/assets/js/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:01 +0330] "GET /wp-content/plugins/woocommerce/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:05 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:00 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:00 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:00 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:00 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:00 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:00 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:00 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:01 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:01 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:05 +0330] "GET /wp-content/themes/classic/inc/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:10 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:13 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:17 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:17 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 500 2 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:17 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:17 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:18 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:18 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:18 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:18 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:22 +0330] "GET /.well-knownold/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:25 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:25 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:25 +0330] "GET /index/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:29 +0330] "GET /id/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:33 +0330] "GET /www/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:27:36 +0330] "GET /web/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:12 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:34 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:19 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:27 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:27 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:27 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:27 +0330] "GET /wp-admin/includes/ HTTP/1.1" 403 787 "-" "-" 156.146.33.74 - - [03/Dec/2025:14:30:27 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "-" "-" 185.177.238.66 - - [03/Dec/2025:15:08:57 +0330] "GET /sevices/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 13; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.7444.102 Mobile Safari/537.36" 182.42.110.255 - - [03/Dec/2025:15:31:19 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 20.51.203.194 - - [03/Dec/2025:16:55:19 +0330] "GET /postnews.php HTTP/1.1" 403 6887 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 18.97.14.80 - - [03/Dec/2025:16:59:45 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 18.97.14.80 - - [03/Dec/2025:16:59:48 +0330] "GET / HTTP/1.1" 301 20 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 66.249.66.40 - - [03/Dec/2025:16:36:23 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.168 - - [03/Dec/2025:16:36:27 +0330] "GET /xmlrpc.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 20.51.203.194 - - [03/Dec/2025:16:55:08 +0330] "GET /userfuns.php HTTP/1.1" 403 6887 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 66.249.66.11 - - [03/Dec/2025:17:13:28 +0330] "GET /wp-config-sample.php HTTP/1.1" 500 1075 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.11 - - [03/Dec/2025:17:16:19 +0330] "GET /wp-blog-header.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.37 - - [03/Dec/2025:17:17:16 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.167 - - [03/Dec/2025:17:25:21 +0330] "GET /images/ HTTP/1.1" 403 787 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 43.156.228.27 - - [03/Dec/2025:17:26:16 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 66.249.66.74 - - [03/Dec/2025:17:34:06 +0330] "GET /wp-activate.php HTTP/1.1" 302 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 18.117.80.205 - - [03/Dec/2025:17:41:13 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 18.117.80.205 - - [03/Dec/2025:17:41:13 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 66.249.66.39 - - [03/Dec/2025:17:42:28 +0330] "GET /wp-trackback.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 45.132.49.182 - - [03/Dec/2025:18:07:41 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 43.130.78.203 - - [03/Dec/2025:18:24:24 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 66.249.66.166 - - [03/Dec/2025:18:52:11 +0330] "GET /kill.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 134.122.8.73 - - [03/Dec/2025:19:16:19 +0330] "GET /.git/config HTTP/1.1" 403 787 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 66.249.66.13 - - [03/Dec/2025:19:32:33 +0330] "GET /wp-content/uploads/2022/05/photo_2022-05-08_15-30-18.jpg HTTP/1.1" 200 98038 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.7390.122 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 45.130.104.242 - - [03/Dec/2025:19:51:23 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 216.73.216.106 - - [03/Dec/2025:20:10:25 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)" 217.103.42.129 - - [03/Dec/2025:20:25:57 +0330] "GET /phpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x44) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.6993.54 Safari/537.36" 217.103.42.129 - - [03/Dec/2025:20:26:19 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 217.103.42.129 - - [03/Dec/2025:20:26:23 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 171.25.193.37 - - [03/Dec/2025:20:26:32 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 171.25.193.37 - - [03/Dec/2025:20:26:39 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 45.84.107.172 - - [03/Dec/2025:20:27:13 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 185.220.101.38 - - [03/Dec/2025:20:27:39 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 217.103.42.129 - - [03/Dec/2025:20:25:52 +0330] "GET /phpmyadmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 [Pinterest/iOS]" 217.103.42.129 - - [03/Dec/2025:20:25:55 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 217.103.42.129 - - [03/Dec/2025:20:26:01 +0330] "GET /PhpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 7.1.0; CPH1909) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Mobile Safari/537.36" 217.103.42.129 - - [03/Dec/2025:20:26:01 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 217.103.42.129 - - [03/Dec/2025:20:26:06 +0330] "GET /pma/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 8.1.0; CPH1909) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Mobile Safari/537.36" 217.103.42.129 - - [03/Dec/2025:20:26:08 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 217.103.42.129 - - [03/Dec/2025:20:26:15 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 217.103.42.129 - - [03/Dec/2025:20:26:27 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 185.177.238.26 - - [03/Dec/2025:20:26:47 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 185.177.238.26 - - [03/Dec/2025:20:26:55 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 109.70.100.68 - - [03/Dec/2025:20:27:04 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 185.129.61.9 - - [03/Dec/2025:20:27:20 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 30.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/532.36" 176.65.149.87 - - [03/Dec/2025:20:29:46 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 176.65.149.87 - - [03/Dec/2025:20:29:53 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 45.138.16.164 - - [03/Dec/2025:20:30:05 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 45.84.107.182 - - [03/Dec/2025:20:30:20 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 45.94.31.68 - - [03/Dec/2025:20:30:30 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 185.220.100.245 - - [03/Dec/2025:20:30:41 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 45.143.200.32 - - [03/Dec/2025:20:31:00 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 185.220.101.132 - - [03/Dec/2025:20:31:09 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 45.239.225.87 - - [03/Dec/2025:20:29:09 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.264 Safari/437.36 PlayStore-Google" 179.60.64.198 - - [03/Dec/2025:21:10:16 +0330] "GET /phpmyadmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 YaBrowser/23.5.1.795 (corp) Yowser/2.5 Safari/537.36" 179.60.64.198 - - [03/Dec/2025:21:10:27 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 11; SM-A505GN Build/RP1A.200720.712; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6834.122 Mobile Safari/537.36 Line/15.0.0/IAB" 179.60.64.198 - - [03/Dec/2025:21:10:33 +0330] "GET /PhpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/437.36 (KHTML, like Gecko) Chrome/126.0.6478.1124 YaBrowser/24.7.1.1124 (beta) Yowser/2.5 Safari/537.36" 179.60.64.198 - - [03/Dec/2025:21:10:43 +0330] "GET /pma/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" 179.60.64.198 - - [03/Dec/2025:21:10:58 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 11; SM-A505GN Build/RP1A.200720.712; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6834.122 Mobile Safari/537.36 Line/15.0.0/IAB" 179.60.64.198 - - [03/Dec/2025:21:10:26 +0330] "GET /phpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/205.1.15 (KHTML, like Gecko) Mobile/35E148 Safari Line/15.19.3" 179.60.64.198 - - [03/Dec/2025:21:10:38 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 11; SM-A505GN Build/RP1A.200720.712; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6834.122 Mobile Safari/537.36 Line/15.0.0/IAB" 179.60.64.198 - - [03/Dec/2025:21:10:48 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Linux; Android 11; SM-A505GN Build/RP1A.200720.712; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6834.122 Mobile Safari/537.36 Line/15.0.0/IAB" 201.119.24.213 - - [03/Dec/2025:21:41:49 +0330] "GET /phpmyadmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_9 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/12A372 Safari/604.1" 201.119.24.213 - - [03/Dec/2025:21:41:58 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 201.119.24.213 - - [03/Dec/2025:21:42:10 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 201.119.24.213 - - [03/Dec/2025:21:42:26 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 201.119.24.213 - - [03/Dec/2025:21:42:32 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 77.48.28.204 - - [03/Dec/2025:21:43:12 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 201.119.24.213 - - [03/Dec/2025:21:41:44 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 201.119.24.213 - - [03/Dec/2025:21:41:50 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 201.119.24.213 - - [03/Dec/2025:21:41:56 +0330] "GET /phpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/14.19.2" 201.119.24.213 - - [03/Dec/2025:21:42:02 +0330] "GET /PhpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" 201.119.24.213 - - [03/Dec/2025:21:42:08 +0330] "GET /pma/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_2_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) GSA/353.1.720273278 Mobile/15E148 Safari/604.1" 201.119.24.213 - - [03/Dec/2025:21:42:19 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 201.119.24.213 - - [03/Dec/2025:21:42:38 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 185.40.4.22 - - [03/Dec/2025:21:42:44 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 45.138.16.231 - - [03/Dec/2025:21:43:04 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 109.70.100.66 - - [03/Dec/2025:21:43:36 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 109.70.100.1 - - [03/Dec/2025:21:43:51 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 185.220.100.254 - - [03/Dec/2025:21:43:56 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 185.220.101.108 - - [03/Dec/2025:21:44:06 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 62.72.47.105 - - [03/Dec/2025:21:44:15 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; Hisense U963 Build/QP1A.190711.020) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.107 Mobile Safari/537.36" 160.179.90.218 - - [03/Dec/2025:22:02:13 +0330] "GET //simi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:02:29 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:02:51 +0330] "GET //Jada.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:02:59 +0330] "GET //zone.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 110.166.71.39 - - [03/Dec/2025:22:03:29 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 160.179.90.218 - - [03/Dec/2025:22:03:31 +0330] "GET //MuPlugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:03:53 +0330] "GET //ObeQY2t7P.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:04:04 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:04:28 +0330] "GET //berax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:04:39 +0330] "GET //ckmail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:05:13 +0330] "GET //database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:05:36 +0330] "GET //db.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:05:59 +0330] "GET //ex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:07:11 +0330] "GET //fix.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:07:21 +0330] "GET //goods.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:07:30 +0330] "GET //inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:07:38 +0330] "GET //item.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:07:45 +0330] "GET //mah.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:02:21 +0330] "GET //rest.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:02:34 +0330] "GET //sx21_1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:02:42 +0330] "GET //login.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:03:07 +0330] "GET //zonexx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:03:17 +0330] "GET //403webshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:03:43 +0330] "GET //O-Simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:04:18 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:04:46 +0330] "GET //click.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:04:56 +0330] "GET //csv.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:05:27 +0330] "GET //database.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:05:44 +0330] "GET //defaults.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:05:52 +0330] "GET //documentroot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:06:23 +0330] "GET //execlude.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:06:51 +0330] "GET //f8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:07:02 +0330] "GET //fix.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:07:53 +0330] "GET //asmtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:08:08 +0330] "GET //malro.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:08:22 +0330] "GET //chosen.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:08:36 +0330] "GET //content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:08:44 +0330] "GET //shop.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:08:52 +0330] "GET //r.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:09:20 +0330] "GET //b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:09:34 +0330] "GET //c.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:09:41 +0330] "GET //e.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:09:55 +0330] "GET //aa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:10:04 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:10:17 +0330] "GET //wordpress.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:10:27 +0330] "GET //core.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:11:20 +0330] "GET //alfanew.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:11:55 +0330] "GET //shell-script.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:12:02 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:12:10 +0330] "GET //simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:12:40 +0330] "GET //rain.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:12:47 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:13:21 +0330] "GET //fw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:13:27 +0330] "GET //ae.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:13:41 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:13:56 +0330] "GET //srx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:14:02 +0330] "GET //1337.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:08:15 +0330] "GET //about.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:09:00 +0330] "GET //y.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:09:10 +0330] "GET //a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:09:48 +0330] "GET //zz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:10:37 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:10:43 +0330] "GET //zossipei.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:10:50 +0330] "GET //lf_utchiha.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:11:00 +0330] "GET //ninjasec.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:11:13 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:11:27 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:11:33 +0330] "GET //utchiha_offer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:11:40 +0330] "GET //style.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:11:48 +0330] "GET //xmlrpc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:12:19 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:12:26 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:12:33 +0330] "GET //xleet.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:12:56 +0330] "GET //dnvokikk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:13:04 +0330] "GET //contents.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:13:13 +0330] "GET //copy.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:13:34 +0330] "GET //glppziux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:13:49 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:14:20 +0330] "GET //doc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:14:26 +0330] "GET //xx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:14:50 +0330] "GET //lf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:15:16 +0330] "GET //alex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:15:30 +0330] "GET //new.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:16:10 +0330] "GET //1index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:16:34 +0330] "GET //wikindex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:16:45 +0330] "GET //wso1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:16:53 +0330] "GET //alfa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:02 +0330] "GET //priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:15 +0330] "GET //m.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:23 +0330] "GET //Lux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:31 +0330] "GET //haxor.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:37 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:45 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:52 +0330] "GET //send.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:59 +0330] "GET //uplo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:18:15 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:18:30 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:18:53 +0330] "GET //wp-mail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:18:57 +0330] "GET //404.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:04 +0330] "GET //asad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:11 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:14:10 +0330] "GET //ups.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:14:34 +0330] "GET //leaf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:14:41 +0330] "GET //leafmailer2.8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:15:38 +0330] "GET //mailer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:15:45 +0330] "GET //marijuana.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:15:53 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:15:59 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:16:22 +0330] "GET //3index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:17:08 +0330] "GET //bb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:18:37 +0330] "GET //wp-content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:18:45 +0330] "GET //wp-upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:25 +0330] "GET //azerty.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:31 +0330] "GET //dell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:38 +0330] "GET //WSO.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:45 +0330] "GET //dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:52 +0330] "GET //cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:20:14 +0330] "GET //mysql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:20:22 +0330] "GET //madspot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:20:38 +0330] "GET //cpbt.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:20:44 +0330] "GET //sYm.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:21:31 +0330] "GET //wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:21:58 +0330] "GET //d0mains.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:18 +0330] "GET //smtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:19:59 +0330] "GET //cpn.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:20:06 +0330] "GET //sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:20:29 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:20:52 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:21:06 +0330] "GET //r99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:21:13 +0330] "GET //lol.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:21:23 +0330] "GET //jo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:21:38 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:21:45 +0330] "GET //shellz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:21:52 +0330] "GET //d0main.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:22:07 +0330] "GET /users.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:22:20 +0330] "GET //killer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:22:27 +0330] "GET //changeall.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:22:49 +0330] "GET //dz0.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:23:24 +0330] "GET //r00t.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:23:57 +0330] "GET //wp.zip HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:24:04 +0330] "GET /madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:24:47 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:22:12 +0330] "GET //Cgishell.pl HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:22:34 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:22:42 +0330] "GET //Sh3ll.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 42.115.244.130 - - [03/Dec/2025:22:22:47 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 160.179.90.218 - - [03/Dec/2025:22:22:56 +0330] "GET //dam.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:23:03 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:23:10 +0330] "GET //dom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:23:17 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:23:31 +0330] "GET //c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:23:38 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:23:50 +0330] "GET //1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:24:08 +0330] "GET //Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:24:17 +0330] "GET //c22.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:24:29 +0330] "GET //c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:24:37 +0330] "GET //Cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:24:55 +0330] "GET //madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:03 +0330] "GET /L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:09 +0330] "GET /d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:18 +0330] "GET /tmp/L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:27 +0330] "GET /upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:32 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:42 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:47 +0330] "GET /sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:52 +0330] "GET /sysadmins/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:59 +0330] "GET /admin1/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:04 +0330] "GET /administration/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:23 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:37 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:43 +0330] "GET //sa2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:50 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:21 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:41 +0330] "GET /dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:45 +0330] "GET /Black.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:02 +0330] "GET /d0maine.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:16 +0330] "GET /dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:21 +0330] "GET /Symlink.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:34 +0330] "GET /sysadmin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:40 +0330] "GET /images/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:13 +0330] "GET /tmp/d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:22 +0330] "GET /admin1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:25:37 +0330] "GET /admin2.asp HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:09 +0330] "GET /images/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:15 +0330] "GET //r57.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:30 +0330] "GET //sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:26:57 +0330] "GET /gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:09 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:13 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:26 +0330] "GET /shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:31 +0330] "GET /amad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:35 +0330] "GET /t00.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:50 +0330] "GET /asp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:27:57 +0330] "GET /whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:07 +0330] "GET /tmp/sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:12 +0330] "GET /tmp/dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:27 +0330] "GET /wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:44 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:28:52 +0330] "GET /c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:10 +0330] "GET /wp-admin/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:25 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:35 +0330] "GET /a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:00 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:05 +0330] "GET /Server.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:20 +0330] "GET /tmp/priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:30 +0330] "GET /admins.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:44 +0330] "GET /1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:53 +0330] "GET /3.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:30:32 +0330] "GET /amhlzdhk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:30:44 +0330] "GET /curl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:30:58 +0330] "GET /index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:05 +0330] "GET /inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:19 +0330] "GET /slax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:28 +0330] "GET /todo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:38 +0330] "GET /txfpcuhw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:42 +0330] "GET /unzipper.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:05 +0330] "GET /webhook.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:10 +0330] "GET /wp-atom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:19 +0330] "GET /wp-pano.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:44 +0330] "GET //shadow.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:51 +0330] "GET //plugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:39 +0330] "GET /w.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:49 +0330] "GET /2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:29:59 +0330] "GET /4.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:30:04 +0330] "GET /5.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:30:26 +0330] "GET /6.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:30:38 +0330] "GET /balance.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:30:49 +0330] "GET /database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:30:53 +0330] "GET /hyivatpf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:10 +0330] "GET /nf_tracking.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:15 +0330] "GET /qkyplyur.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:24 +0330] "GET /tesTlme.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:33 +0330] "GET /ttcecnmc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:47 +0330] "GET /unZIPpeRqyr.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:51 +0330] "GET /ut.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:31:56 +0330] "GET /utchiha2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:00 +0330] "GET /uuhoxcyb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:23 +0330] "GET /wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:29 +0330] "GET /zvpqaqfb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [03/Dec/2025:22:32:35 +0330] "GET //xl2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 150.107.246.217 - - [03/Dec/2025:22:40:01 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 4.241.208.113 - - [03/Dec/2025:22:51:33 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [03/Dec/2025:22:51:33 +0330] "GET / HTTP/1.1" 403 17364 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [03/Dec/2025:22:51:34 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [03/Dec/2025:22:51:33 +0330] "POST /wp-plain.php HTTP/1.1" 404 101828 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 142.248.80.88 - - [03/Dec/2025:22:46:10 +0330] "GET /wp-admin/setup-config.php HTTP/1.1" 409 2838 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 4.241.208.113 - - [03/Dec/2025:22:51:33 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 72.195.34.35 - - [03/Dec/2025:23:34:26 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 72.195.34.35 - - [03/Dec/2025:23:34:43 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 72.195.34.35 - - [03/Dec/2025:23:34:51 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 154.50.28.230 - - [03/Dec/2025:23:45:55 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "python-httpx/0.28.1" 154.50.28.230 - - [03/Dec/2025:23:46:07 +0330] "GET /wp-admin/css/colors/blue/chosen.php HTTP/1.1" 301 20 "-" "python-httpx/0.28.1" 72.195.34.35 - - [03/Dec/2025:23:34:35 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 154.50.28.230 - - [03/Dec/2025:23:46:00 +0330] "GET /about.php HTTP/1.1" 301 20 "-" "python-httpx/0.28.1" 4.241.192.251 - - [03/Dec/2025:23:55:36 +0330] "GET /abcd.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:23:55:54 +0330] "GET /akcc.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:23:56:03 +0330] "GET /xmrlpc.php HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:23:56:13 +0330] "GET /xmlrpc.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:23:56:19 +0330] "GET /api.php HTTP/1.1" 301 0 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:23:56:29 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 181.46.71.10 - - [03/Dec/2025:23:56:37 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 4.241.192.251 - - [03/Dec/2025:23:56:39 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:23:56:39 +0330] "GET /cgi-bin/file.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 181.46.71.10 - - [03/Dec/2025:23:56:42 +0330] "GET /phpmyadmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Safari/605.1.15" 181.46.71.10 - - [03/Dec/2025:23:56:44 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 181.46.71.10 - - [03/Dec/2025:23:56:50 +0330] "GET /phpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 02.0; SM-A17 5G Build/MRA58K; wv) AppleWebKit/537.32 (KHTML, like Gecko) Version/4.0 Chrome/95.0.4638.74 Mobile Safari/537.36" 181.46.71.10 - - [03/Dec/2025:23:56:55 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 4.241.192.251 - - [03/Dec/2025:23:56:58 +0330] "GET /classwithtostring.php HTTP/1.1" 301 0 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 181.46.71.10 - - [03/Dec/2025:23:57:04 +0330] "GET /pma/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 14; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6834.163 Mobile Safari/537.36 Line/15.0.0/IAB" 181.46.71.10 - - [03/Dec/2025:23:57:08 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 4.241.192.251 - - [03/Dec/2025:23:57:16 +0330] "GET /edit.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 181.46.71.10 - - [03/Dec/2025:23:57:28 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 181.46.71.10 - - [03/Dec/2025:23:57:35 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 181.46.71.10 - - [03/Dec/2025:23:57:41 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 45.84.107.97 - - [03/Dec/2025:23:58:32 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 23.129.64.175 - - [03/Dec/2025:23:58:55 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 185.129.61.4 - - [03/Dec/2025:23:59:06 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 185.220.100.254 - - [03/Dec/2025:23:59:24 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 4.241.192.251 - - [03/Dec/2025:23:55:46 +0330] "GET /admin.php HTTP/1.1" 301 0 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 4.241.192.251 - - [03/Dec/2025:23:56:48 +0330] "GET /chosen.php HTTP/1.1" 301 0 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 181.46.71.10 - - [03/Dec/2025:23:56:58 +0330] "GET /PhpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 Viewer/99.9.9041.90" 4.241.192.251 - - [03/Dec/2025:23:57:07 +0330] "GET /cong.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 181.46.71.10 - - [03/Dec/2025:23:57:20 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 4.241.192.251 - - [03/Dec/2025:23:57:25 +0330] "GET /new.php HTTP/1.1" 301 0 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 4.241.192.251 - - [03/Dec/2025:23:57:37 +0330] "GET /NewFile.php HTTP/1.1" 301 0 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 185.220.101.107 - - [03/Dec/2025:23:57:50 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 185.220.101.107 - - [03/Dec/2025:23:57:57 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 185.156.72.7 - - [03/Dec/2025:23:58:07 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 185.220.101.183 - - [03/Dec/2025:23:58:45 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 44; SM-S9010 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6234.163 Mobile Safari/537.36 Line/15.0.0/IAB" 160.179.90.218 - - [04/Dec/2025:00:06:04 +0330] "GET //sx21_1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:06:12 +0330] "GET //login.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:06:19 +0330] "GET //Jada.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:06:26 +0330] "GET //zone.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:06:33 +0330] "GET //zonexx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:06:39 +0330] "GET //403webshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:06:46 +0330] "GET //MuPlugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:27 +0330] "GET //ckmail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:40 +0330] "GET //csv.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:46 +0330] "GET //database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:53 +0330] "GET //database.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:08:05 +0330] "GET //defaults.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:08:12 +0330] "GET //documentroot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:08:19 +0330] "GET //ex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:08:26 +0330] "GET //execlude.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:08:46 +0330] "GET //fix.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:08:53 +0330] "GET //goods.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:07 +0330] "GET //item.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:29 +0330] "GET //malro.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:58 +0330] "GET //shop.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:18 +0330] "GET //a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:38 +0330] "GET //e.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:05:45 +0330] "GET //simi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:05:53 +0330] "GET //rest.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:05:59 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:06:52 +0330] "GET //O-Simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:06:59 +0330] "GET //ObeQY2t7P.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:05 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:14 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:21 +0330] "GET //berax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:34 +0330] "GET //click.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:07:59 +0330] "GET //db.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:08:32 +0330] "GET //f8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:08:40 +0330] "GET //fix.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:00 +0330] "GET //inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:13 +0330] "GET //mah.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:23 +0330] "GET //asmtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:36 +0330] "GET //about.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:44 +0330] "GET //chosen.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:09:51 +0330] "GET //content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:05 +0330] "GET //r.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:11 +0330] "GET //y.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:24 +0330] "GET //b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:31 +0330] "GET //c.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:44 +0330] "GET //zz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:51 +0330] "GET //aa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:10:58 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:11:05 +0330] "GET //wordpress.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:11:20 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:11:41 +0330] "GET //ninjasec.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:00 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:20 +0330] "GET //xmlrpc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:31 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:37 +0330] "GET //simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:57 +0330] "GET //xleet.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:04 +0330] "GET //rain.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:18 +0330] "GET //dnvokikk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:25 +0330] "GET //contents.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:31 +0330] "GET //copy.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:11:13 +0330] "GET //core.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:11:27 +0330] "GET //zossipei.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:11:34 +0330] "GET //lf_utchiha.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:11:47 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:11:54 +0330] "GET //alfanew.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:07 +0330] "GET //utchiha_offer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:14 +0330] "GET //style.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:24 +0330] "GET //shell-script.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:44 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:12:50 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:11 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:37 +0330] "GET //fw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:44 +0330] "GET //ae.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:14:10 +0330] "GET //srx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:14:17 +0330] "GET //1337.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:14:24 +0330] "GET //ups.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:14:44 +0330] "GET //leaf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:14:58 +0330] "GET //lf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:05 +0330] "GET //alex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:18 +0330] "GET //mailer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:25 +0330] "GET //marijuana.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:33 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:40 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:52 +0330] "GET //3index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:06 +0330] "GET //wso1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:13 +0330] "GET //alfa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:26 +0330] "GET //bb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:39 +0330] "GET //Lux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:47 +0330] "GET //haxor.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:53 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:59 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:06 +0330] "GET //send.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:35 +0330] "GET //wp-content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:51 +0330] "GET //glppziux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:13:57 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:14:04 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:14:30 +0330] "GET //doc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:14:36 +0330] "GET //xx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 43.155.195.141 - - [04/Dec/2025:00:14:38 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 160.179.90.218 - - [04/Dec/2025:00:14:51 +0330] "GET //leafmailer2.8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:12 +0330] "GET //new.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:46 +0330] "GET //1index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:15:59 +0330] "GET //wikindex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:19 +0330] "GET //priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:16:32 +0330] "GET //m.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:13 +0330] "GET //uplo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:20 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:27 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:48 +0330] "GET //wp-mail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:06 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:12 +0330] "GET //smtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:25 +0330] "GET //dell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:45 +0330] "GET //cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:19:06 +0330] "GET //mysql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:19:26 +0330] "GET //cpbt.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:42 +0330] "GET //wp-upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:52 +0330] "GET //404.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:17:59 +0330] "GET //asad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:19 +0330] "GET //azerty.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:32 +0330] "GET //WSO.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:39 +0330] "GET //dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:52 +0330] "GET //cpn.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:18:59 +0330] "GET //sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:19:13 +0330] "GET //madspot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:19:19 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:19:47 +0330] "GET //r99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:00 +0330] "GET //jo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:07 +0330] "GET //wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:20 +0330] "GET //shellz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:27 +0330] "GET //d0main.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:34 +0330] "GET //d0mains.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:46 +0330] "GET //Cgishell.pl HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:21 +0330] "GET //dz0.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:37 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:44 +0330] "GET //dom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:12 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:19 +0330] "GET //1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:19:33 +0330] "GET //sYm.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:19:39 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:19:53 +0330] "GET //lol.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:14 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:41 +0330] "GET /users.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:20:53 +0330] "GET //killer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:00 +0330] "GET //changeall.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:07 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:14 +0330] "GET //Sh3ll.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:30 +0330] "GET //dam.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:52 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:21:59 +0330] "GET //r00t.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:06 +0330] "GET //c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:32 +0330] "GET /madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:36 +0330] "GET //Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:49 +0330] "GET //c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:56 +0330] "GET //Cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:03 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:16 +0330] "GET /L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:21 +0330] "GET /d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:39 +0330] "GET /upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:44 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:48 +0330] "GET /admin2.asp HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:57 +0330] "GET /sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:01 +0330] "GET /sysadmins/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:06 +0330] "GET /admin1/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:11 +0330] "GET /administration/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:16 +0330] "GET /images/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:20 +0330] "GET //r57.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:26 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:33 +0330] "GET //sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:53 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:08 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:43 +0330] "GET /asp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:52 +0330] "GET /d0maine.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:25 +0330] "GET //wp.zip HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:22:42 +0330] "GET //c22.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:10 +0330] "GET //madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:25 +0330] "GET /tmp/d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:30 +0330] "GET /tmp/L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:34 +0330] "GET /admin1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:23:53 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:40 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:24:47 +0330] "GET //sa2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:00 +0330] "GET /gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:04 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:15 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:19 +0330] "GET /shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:23 +0330] "GET /amad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:28 +0330] "GET /t00.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:33 +0330] "GET /dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:37 +0330] "GET /Black.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:48 +0330] "GET /whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:01 +0330] "GET /tmp/dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:06 +0330] "GET /dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:10 +0330] "GET /Symlink.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:14 +0330] "GET /wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:23 +0330] "GET /images/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:28 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:32 +0330] "GET /c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:36 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:41 +0330] "GET /Server.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:58 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:02 +0330] "GET /admins.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:11 +0330] "GET /w.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:15 +0330] "GET /1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:24 +0330] "GET /3.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:29 +0330] "GET /4.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:34 +0330] "GET /5.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:43 +0330] "GET /amhlzdhk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:03 +0330] "GET /hyivatpf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:07 +0330] "GET /index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:18 +0330] "GET /nf_tracking.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:31 +0330] "GET /tesTlme.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:36 +0330] "GET /todo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:40 +0330] "GET /ttcecnmc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:45 +0330] "GET /txfpcuhw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:49 +0330] "GET /unzipper.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:54 +0330] "GET /unZIPpeRqyr.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:25:56 +0330] "GET /tmp/sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:19 +0330] "GET /sysadmin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:45 +0330] "GET /wp-admin/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:26:53 +0330] "GET /tmp/priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:06 +0330] "GET /a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:20 +0330] "GET /2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:38 +0330] "GET /6.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:48 +0330] "GET /balance.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:53 +0330] "GET /curl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:27:58 +0330] "GET /database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:14 +0330] "GET /inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:22 +0330] "GET /qkyplyur.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:28:27 +0330] "GET /slax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:04 +0330] "GET /utchiha2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:17 +0330] "GET /wp-atom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:29 +0330] "GET /wqjtejxi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:33 +0330] "GET /wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:38 +0330] "GET /zvpqaqfb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:42 +0330] "GET //xl2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:48 +0330] "GET //shadow.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 45.149.173.235 - - [04/Dec/2025:00:39:02 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 160.179.90.218 - - [04/Dec/2025:00:28:59 +0330] "GET /ut.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:08 +0330] "GET /uuhoxcyb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:13 +0330] "GET /webhook.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:24 +0330] "GET /wp-pano.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 160.179.90.218 - - [04/Dec/2025:00:29:54 +0330] "GET //plugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:52:21 +0330] "GET //simi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:52:35 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:52:46 +0330] "GET //login.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:52:52 +0330] "GET //Jada.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:52:59 +0330] "GET //zone.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:05 +0330] "GET //zonexx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:18 +0330] "GET //MuPlugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:24 +0330] "GET //O-Simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:31 +0330] "GET //ObeQY2t7P.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:37 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:44 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:50 +0330] "GET //berax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:03 +0330] "GET //click.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:16 +0330] "GET //database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:23 +0330] "GET //database.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:36 +0330] "GET //defaults.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:43 +0330] "GET //documentroot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:55 +0330] "GET //execlude.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:01 +0330] "GET //f8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:21 +0330] "GET //goods.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:27 +0330] "GET //inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:34 +0330] "GET //item.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:52:29 +0330] "GET //rest.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:52:40 +0330] "GET //sx21_1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:11 +0330] "GET //403webshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:53:56 +0330] "GET //ckmail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:09 +0330] "GET //csv.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:30 +0330] "GET //db.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:54:49 +0330] "GET //ex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:08 +0330] "GET //fix.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:15 +0330] "GET //fix.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:40 +0330] "GET //mah.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:53 +0330] "GET //malro.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:13 +0330] "GET //content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:33 +0330] "GET //y.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:39 +0330] "GET //a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:46 +0330] "GET //b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:52 +0330] "GET //c.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:58 +0330] "GET //e.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:05 +0330] "GET //zz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:11 +0330] "GET //aa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:24 +0330] "GET //wordpress.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:31 +0330] "GET //core.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:37 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:44 +0330] "GET //zossipei.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:50 +0330] "GET //lf_utchiha.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:57 +0330] "GET //ninjasec.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:16 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:23 +0330] "GET //utchiha_offer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:35 +0330] "GET //xmlrpc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:39 +0330] "GET //shell-script.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 46.148.206.226 - - [04/Dec/2025:00:58:40 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 41.249.48.189 - - [04/Dec/2025:00:58:45 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:59:05 +0330] "GET //wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:47 +0330] "GET //asmtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:55:59 +0330] "GET //about.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:06 +0330] "GET //chosen.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:19 +0330] "GET //shop.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:56:26 +0330] "GET //r.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:57:18 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:03 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:10 +0330] "GET //alfanew.php7 HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:29 +0330] "GET //style.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:52 +0330] "GET //simple.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:58:58 +0330] "GET //atomlib.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:59:11 +0330] "GET //xleet.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:59:18 +0330] "GET //rain.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:59:24 +0330] "GET //rdpl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:59:31 +0330] "GET //dnvokikk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:59:37 +0330] "GET //contents.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:59:43 +0330] "GET //copy.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:00:03 +0330] "GET //glppziux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:00:10 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:00:48 +0330] "GET //1337.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:01:15 +0330] "GET //doc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:01:36 +0330] "GET //xx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 62.234.206.73 - - [04/Dec/2025:00:59:10 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.249.48.189 - - [04/Dec/2025:00:59:50 +0330] "GET //fw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:00:59:56 +0330] "GET //ae.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:00:17 +0330] "GET //wso.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:00:24 +0330] "GET //srx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:00:59 +0330] "GET //ups.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:01:52 +0330] "GET //leafmailer2.8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:01:58 +0330] "GET //lf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:05 +0330] "GET //alex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:12 +0330] "GET //new.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:19 +0330] "GET //mailer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:32 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:39 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:59 +0330] "GET //wikindex.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:03:20 +0330] "GET //priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:03:53 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:20 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:40 +0330] "GET //wp-upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:46 +0330] "GET //wp-mail.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:56 +0330] "GET //asad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:10 +0330] "GET //smtp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:16 +0330] "GET //azerty.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:01:44 +0330] "GET //leaf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:25 +0330] "GET //marijuana.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:45 +0330] "GET //1index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:02:52 +0330] "GET //3index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:03:06 +0330] "GET //wso1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:03:13 +0330] "GET //alfa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:03:27 +0330] "GET //bb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:03:33 +0330] "GET //m.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:03:39 +0330] "GET //Lux.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:03:46 +0330] "GET //haxor.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:00 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:06 +0330] "GET //send.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:13 +0330] "GET //uplo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:26 +0330] "GET //osx.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:33 +0330] "GET //wp-content.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:04:50 +0330] "GET //404.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:03 +0330] "GET //wp-admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:29 +0330] "GET //WSO.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:36 +0330] "GET //dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:43 +0330] "GET //cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:56 +0330] "GET //sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:09 +0330] "GET //madspot.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:23 +0330] "GET //dell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:05:49 +0330] "GET //cpn.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:03 +0330] "GET //mysql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:23 +0330] "GET //cpbt.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:36 +0330] "GET //x.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:49 +0330] "GET //lol.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:03 +0330] "GET //wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:10 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:34 +0330] "GET /users.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:39 +0330] "GET //Cgishell.pl HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:45 +0330] "GET //killer.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:52 +0330] "GET //changeall.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:58 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:08:12 +0330] "GET //dz0.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:08:19 +0330] "GET //dam.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:08:41 +0330] "GET //whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:08 +0330] "GET //1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:15 +0330] "GET //wp.zip HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:22 +0330] "GET /madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:34 +0330] "GET //c22.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:41 +0330] "GET //c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:09 +0330] "GET /L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:16 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:29 +0330] "GET //sYm.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:42 +0330] "GET //r99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:06:55 +0330] "GET //jo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:16 +0330] "GET //shellz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:22 +0330] "GET //d0main.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:07:28 +0330] "GET //d0mains.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 5.45.79.23 - - [04/Dec/2025:01:07:59 +0330] "GET /wp-content/plugins/whmcs-bridge/cc.css HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1.2 Safari/605.1.15" 41.249.48.189 - - [04/Dec/2025:01:08:05 +0330] "GET //Sh3ll.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:08:26 +0330] "GET //user.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:08:34 +0330] "GET //dom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:08:48 +0330] "GET //r00t.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:08:55 +0330] "GET //c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:02 +0330] "GET //gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:27 +0330] "GET //Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:47 +0330] "GET //Cpanel.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:09:54 +0330] "GET //cp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:02 +0330] "GET //madspotshell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:18 +0330] "GET /tmp/d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:37 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:41 +0330] "GET /admin2.asp HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:56 +0330] "GET /sysadmins/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:11 +0330] "GET /images/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:16 +0330] "GET //r57.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:29 +0330] "GET //sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:36 +0330] "GET //admin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:42 +0330] "GET //sa2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:49 +0330] "GET //2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:56 +0330] "GET /gaza.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:13 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:17 +0330] "GET /shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:22 +0330] "GET /amad.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:13 +0330] "GET /d.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:23 +0330] "GET /tmp/L3b.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:27 +0330] "GET /admin1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:32 +0330] "GET /upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:46 +0330] "GET /uploads.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:10:51 +0330] "GET /sa.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:01 +0330] "GET /admin1/ HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:06 +0330] "GET /administration/Sym.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:11:22 +0330] "GET //shell.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:01 +0330] "GET /up.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:06 +0330] "GET //upload.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:26 +0330] "GET /t00.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:43 +0330] "GET /whmcs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:48 +0330] "GET /d0maine.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:03 +0330] "GET /dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:12 +0330] "GET /wp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:21 +0330] "GET /images/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:30 +0330] "GET /c100.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:35 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:44 +0330] "GET /wp-admin/c99.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:52 +0330] "GET /tmp/priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:15 +0330] "GET /1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 124.156.179.141 - - [04/Dec/2025:01:14:22 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 41.249.48.189 - - [04/Dec/2025:01:14:28 +0330] "GET /4.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:33 +0330] "GET /5.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:38 +0330] "GET /6.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:42 +0330] "GET /amhlzdhk.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:47 +0330] "GET /balance.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:52 +0330] "GET /curl.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:01 +0330] "GET /hyivatpf.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:05 +0330] "GET /index.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:13 +0330] "GET /inputs.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:31 +0330] "GET /tesTlme.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:35 +0330] "GET /todo.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:31 +0330] "GET /dz.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:35 +0330] "GET /Black.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:39 +0330] "GET /asp.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:53 +0330] "GET /tmp/sql.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:12:58 +0330] "GET /tmp/dz1.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:07 +0330] "GET /Symlink.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:17 +0330] "GET /sysadmin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:25 +0330] "GET /xd.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:39 +0330] "GET /Server.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:13:57 +0330] "GET /priv8.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:01 +0330] "GET /admins.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:05 +0330] "GET /a.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:10 +0330] "GET /w.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:19 +0330] "GET /2.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:24 +0330] "GET /3.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:14:57 +0330] "GET /database.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:17 +0330] "GET /nf_tracking.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:22 +0330] "GET /qkyplyur.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:26 +0330] "GET /slax.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:40 +0330] "GET /ttcecnmc.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:49 +0330] "GET /unzipper.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:54 +0330] "GET /unZIPpeRqyr.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:06 +0330] "GET /uuhoxcyb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:16 +0330] "GET /wp-atom.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:28 +0330] "GET /wqjtejxi.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:46 +0330] "GET //shadow.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:54 +0330] "GET //plugin.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:44 +0330] "GET /txfpcuhw.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:15:58 +0330] "GET /ut.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:02 +0330] "GET /utchiha2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:11 +0330] "GET /webhook.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:23 +0330] "GET /wp-pano.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:32 +0330] "GET /wso112233.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:36 +0330] "GET /zvpqaqfb.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 41.249.48.189 - - [04/Dec/2025:01:16:40 +0330] "GET //xl2023.php HTTP/1.1" 301 20 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 45.131.155.100 - - [04/Dec/2025:01:29:06 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.6 Safari/605.1.15" 45.131.155.100 - - [04/Dec/2025:01:29:07 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" 157.230.31.114 - - [04/Dec/2025:01:43:02 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 45.82.78.114 - - [04/Dec/2025:01:29:14 +0330] "GET /favicon.ico HTTP/1.1" 404 796 "http://optimyar.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36" 199.244.88.219 - - [04/Dec/2025:01:52:54 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 88.210.3.196 - - [04/Dec/2025:02:25:00 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 216.24.212.217 - - [04/Dec/2025:02:31:43 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 216.24.212.236 - - [04/Dec/2025:02:31:51 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 216.24.212.221 - - [04/Dec/2025:02:31:59 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 216.24.212.217 - - [04/Dec/2025:02:32:06 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 CCleaner/130.0.0.0" 41.182.10.251 - - [04/Dec/2025:02:39:06 +0330] "GET /phpmyadmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:12 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:21 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:24 +0330] "GET /pma/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/597.30 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:35 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 185.129.62.64 - - [04/Dec/2025:02:40:02 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 185.129.62.64 - - [04/Dec/2025:02:40:11 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 45.84.107.172 - - [04/Dec/2025:02:40:58 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 185.40.4.149 - - [04/Dec/2025:02:41:09 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 169.239.181.213 - - [04/Dec/2025:02:48:21 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:00 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:05 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:12 +0330] "GET /phpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1 Safari/605.1.15" 41.182.10.251 - - [04/Dec/2025:02:39:19 +0330] "GET /PhpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X81; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/125.0.5173.0 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:29 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:40 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 41.182.10.251 - - [04/Dec/2025:02:39:45 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 45.138.16.248 - - [04/Dec/2025:02:40:21 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 45.128.133.242 - - [04/Dec/2025:02:40:35 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 185.220.101.96 - - [04/Dec/2025:02:40:48 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/530.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" 37.60.246.231 - - [04/Dec/2025:03:07:11 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 61.64.20.198 - - [04/Dec/2025:03:16:51 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 61.64.20.198 - - [04/Dec/2025:03:16:58 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 175.182.67.212 - - [04/Dec/2025:03:17:22 +0330] "GET /pma/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 14; SM-S9210 Build/UP1A.231005.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/131.0.6778.261 Mobile Safari/537.36 Line/15.0.0/IAB" 175.182.67.212 - - [04/Dec/2025:03:17:24 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 61.64.20.198 - - [04/Dec/2025:03:17:30 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 61.64.20.198 - - [04/Dec/2025:03:17:36 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 175.182.67.212 - - [04/Dec/2025:03:17:42 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 185.220.101.101 - - [04/Dec/2025:03:18:03 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 124.198.132.13 - - [04/Dec/2025:03:18:16 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 185.220.101.107 - - [04/Dec/2025:03:18:29 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 109.70.100.66 - - [04/Dec/2025:03:18:46 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 61.64.20.198 - - [04/Dec/2025:03:17:02 +0330] "GET /phpmyadmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 14; V2144 Build/UP1A.231705.007; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6834.122 Mobile Safari/537.36 Line/15.0.0/IAB" 61.64.20.198 - - [04/Dec/2025:03:17:06 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 61.64.20.198 - - [04/Dec/2025:03:17:09 +0330] "GET /phpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Linux; Android 10; H9493 Build/52.1.A.3.137; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/132.0.6834.163 Mobile Safari/537.36 Line/10.9.1/IAB" 61.64.20.198 - - [04/Dec/2025:03:17:15 +0330] "GET /PhpMyAdmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 3.1; rv:40.0) Gecko/40100104 Firefox/40.0" 61.64.20.198 - - [04/Dec/2025:03:17:16 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 45.84.107.47 - - [04/Dec/2025:03:18:38 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 185.220.100.249 - - [04/Dec/2025:03:18:57 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 109.70.100.65 - - [04/Dec/2025:03:19:04 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/24.0 Chrome/117.0.0.0 Safari/537.36" 57.131.24.47 - - [04/Dec/2025:03:22:07 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36" 45.239.225.87 - - [04/Dec/2025:03:46:58 +0330] "GET /phpmyadmin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 8.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/6.7.3 Chrome/118.0.5993.220 Safari/537.36" 45.239.225.87 - - [04/Dec/2025:03:47:06 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 66.249.66.76 - - [04/Dec/2025:03:47:41 +0330] "GET /wp-content/uploads/2022/05/photo_2022-05-08_15-30-18.jpg HTTP/1.1" 304 0 "-" "Googlebot-Image/1.0" 217.182.75.199 - - [04/Dec/2025:03:48:51 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 217.182.75.199 - - [04/Dec/2025:03:49:01 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 109.70.100.2 - - [04/Dec/2025:03:49:11 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 185.231.33.38 - - [04/Dec/2025:03:49:19 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 185.40.4.101 - - [04/Dec/2025:03:49:28 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 45.84.107.47 - - [04/Dec/2025:03:49:35 +0330] "GET /admin/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 45.239.225.87 - - [04/Dec/2025:03:47:22 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 45.239.225.87 - - [04/Dec/2025:03:47:34 +0330] "GET /wp-admin/ HTTP/1.1" 301 20 "https://optimyar.com/not-found/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 45.239.225.87 - - [04/Dec/2025:03:47:35 +0330] "GET /pma/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/20D67 Instagram 364.0.0.20.92 (iPhone12,1; iOS 46_3_1; ko_KR; ko; scale=2.00; 828x1792; 686006448; IABMV/1)" 45.239.225.87 - - [04/Dec/2025:03:47:50 +0330] "GET /admin.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 45.239.225.87 - - [04/Dec/2025:03:48:14 +0330] "GET /admin HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 217.182.75.199 - - [04/Dec/2025:03:48:36 +0330] "GET /administrator/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 217.182.75.199 - - [04/Dec/2025:03:48:42 +0330] "GET /administrator/index.php HTTP/1.1" 301 20 "https://optimyar.com/administrator/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/606.1.15 (KHTML, like Gecko) Mobile/15E148 Safari Line/15.5.4" 182.42.105.144 - - [04/Dec/2025:04:16:23 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 37.228.206.114 - - [04/Dec/2025:04:28:47 +0330] "GET /courses/ HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36" 180.254.108.94 - - [04/Dec/2025:05:13:19 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 185.117.225.127 - - [04/Dec/2025:05:28:29 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "python-requests/2.31.0" 185.117.225.127 - - [04/Dec/2025:05:28:34 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36 BitSightBot/1.0" 80.124.54.14 - - [04/Dec/2025:05:34:08 +0330] "GET /wp-info.php HTTP/1.1" 301 20 "-" "python-requests/2.27.1" 80.124.54.14 - - [04/Dec/2025:05:34:17 +0330] "GET /alfanew.php7 HTTP/1.1" 301 20 "-" "python-requests/2.27.1" 205.169.39.46 - - [04/Dec/2025:05:37:02 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:22 +0330] "GET /atomlib.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:23 +0330] "GET /simple.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:24 +0330] "GET /bypass.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:25 +0330] "GET /alfanew.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:26 +0330] "GET /fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:23 +0330] "GET /css.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:23 +0330] "GET /wp-config.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:24 +0330] "GET /shell.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:25 +0330] "GET /ws.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:25 +0330] "GET /wso112233.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.124.54.14 - - [04/Dec/2025:05:50:27 +0330] "GET /wp-login.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.102.55.18 - - [04/Dec/2025:05:56:19 +0330] "GET /wp-content/themes/torofilm/readme.txt HTTP/1.1" 301 20 "-" "python-requests/2.31.0" 161.35.78.173 - - [04/Dec/2025:06:40:23 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 10.0; Win64; x64; Trident/6.0)" 64.227.180.211 - - [04/Dec/2025:07:12:04 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 43.135.36.201 - - [04/Dec/2025:07:07:40 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 195.24.236.120 - - [04/Dec/2025:07:26:15 +0330] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 4.241.208.113 - - [04/Dec/2025:07:36:27 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [04/Dec/2025:07:36:27 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [04/Dec/2025:07:36:27 +0330] "GET / HTTP/1.1" 403 17362 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [04/Dec/2025:07:36:28 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [04/Dec/2025:07:36:27 +0330] "POST /wp-plain.php HTTP/1.1" 404 101828 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 4.241.208.113 - - [04/Dec/2025:07:36:32 +0330] "GET /zmatojng.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 44.195.201.244 - - [04/Dec/2025:07:43:22 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:43:37 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:44:24 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:45:11 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:45:27 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:43:53 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:44:08 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:44:39 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:44:55 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:45:43 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:45:59 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:46:14 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:46:31 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:46:46 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:47:02 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:47:18 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)" 44.195.201.244 - - [04/Dec/2025:07:47:34 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5 (TestUserAgent)"