41.248.122.22 - - [19/Nov/2025:15:51:36 +0330] "POST /wp-content/plugins/wp-file-manager/lib/php/connector.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:51:59 +0330] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:52:28 +0330] "GET /class-db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:53:04 +0330] "GET /wp-admin/class-db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 41.248.122.22 - - [19/Nov/2025:15:53:15 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:53:46 +0330] "GET /item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 41.248.122.22 - - [19/Nov/2025:15:53:55 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:54:23 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:54:33 +0330] "POST /wp-admin/admin-ajax.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 41.248.122.22 - - [19/Nov/2025:15:54:47 +0330] "GET /wp-content/uploads/theme_4949.php?dark07x=ZWNobyBEQVJLMDdYX0dIT1NUX1RIRU1F HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 43.135.138.128 - - [19/Nov/2025:15:54:57 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 41.248.122.22 - - [19/Nov/2025:15:55:28 +0330] "GET /wp-content/plugins/revslider/temp/update_extract/revslider/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:55:37 +0330] "GET /wp-content/plugins/formcraft/lib/upload.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 41.248.122.22 - - [19/Nov/2025:15:55:49 +0330] "GET /wp-content/plugins/quiz-maker/quiz-maker.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:07:57 +0330] "GET /wp-content/plugins/w0rdpr3ssnew/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:08:04 +0330] "GET /wp-content/plugins/w0rdpr3ssnew/about.phpp HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:08:15 +0330] "GET /wp-content/plugins/ccx/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:08:29 +0330] "GET /wp-admin/includes/xleet-shell.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:51:16 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:51:21 +0330] "POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 41.248.122.22 - - [19/Nov/2025:15:51:27 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/ghost_5245.php?dark07x=ZWNobyBEQVJLMDdYX0dIT1NUX1NVQ0NFU1M= HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:51:40 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/ghost_5245.php?dark07x=ZWNobyBEQVJLMDdYX0dIT1NUX1NVQ0NFU1M= HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 41.248.122.22 - - [19/Nov/2025:15:51:46 +0330] "GET /wp-content/plugins/seoplugins/mar.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:52:09 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:52:23 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:52:34 +0330] "GET /wp-content/class-db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:52:44 +0330] "GET /wp-includes/class-db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:53:22 +0330] "GET /radio.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 41.248.122.22 - - [19/Nov/2025:15:53:44 +0330] "GET /flower.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 41.248.122.22 - - [19/Nov/2025:15:54:02 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:54:16 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:54:28 +0330] "GET /wp-content/plugins/not/includes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:55:00 +0330] "POST /wp-admin/async-upload.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:15:55:16 +0330] "GET /wp-content/uploads/theme_4949.php?dark07x=ZWNobyBEQVJLMDdYX0dIT1NUX1RIRU1F HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:09:48 +0330] "GET /class-db.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:13:32 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:19:14 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:21:41 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:22:23 +0330] "GET /wp-content/plugins/not/includes/about.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:49:30 +0330] "GET /404.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:49:49 +0330] "GET /radio.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:50:38 +0330] "GET /woh.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:50:47 +0330] "GET /wp-config-sample.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:50:58 +0330] "GET /wp-admin/images/Mhbgf.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:51:09 +0330] "GET /class.api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:51:53 +0330] "GET /ws.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:52:32 +0330] "GET /wp-includes/plugins/instabuilder2/cache/plugins/moon.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:52:42 +0330] "GET /wp-admin/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:53:17 +0330] "GET /css/st.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:53:27 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:53:47 +0330] "GET /mah.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:54:08 +0330] "GET /uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:54:43 +0330] "GET /chosen.php?p= HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:54:54 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 41.248.122.22 - - [19/Nov/2025:16:08:36 +0330] "GET /fosil.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:49:38 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:49:58 +0330] "GET /xx.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:50:08 +0330] "GET /Njima.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:50:17 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:50:26 +0330] "GET /wso.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:51:17 +0330] "GET /about.php?525 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:51:30 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:51:41 +0330] "GET /wp-content/alfa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:52:02 +0330] "GET /up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:52:12 +0330] "GET /simple.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:52:24 +0330] "GET /cache-compat.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:52:52 +0330] "GET /wp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:53:03 +0330] "GET /mah.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:53:37 +0330] "GET /defaults.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:53:56 +0330] "GET /install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:54:19 +0330] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:54:33 +0330] "GET /about.php?p= HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:55:04 +0330] "GET /leafmailer2.8.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:55:14 +0330] "GET /leaf.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:55:24 +0330] "GET /lf.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:55:44 +0330] "GET /wp-conetnt/leaf.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:56:06 +0330] "GET /wp-content/leafmailer2.8.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:56:18 +0330] "GET /wp-admin/leafmailer2.8.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:56:33 +0330] "GET /mailer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:56:46 +0330] "GET /leaf-mailer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:56:58 +0330] "GET /send.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:57:37 +0330] "GET /m.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:57:48 +0330] "GET /alexus-mailer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:57:58 +0330] "GET /mail.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:58:25 +0330] "GET /inputs.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:58:36 +0330] "GET /wp-content/plugins/WordPressCore/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:58:45 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:58:53 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:59:00 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:59:08 +0330] "GET /wp-content/plugins/pwnd/pwnd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:59:20 +0330] "GET /wp-includes/Requests/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:55:33 +0330] "GET /leafmailer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:55:55 +0330] "GET /wp-admin/leaf.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:57:07 +0330] "GET /sender.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:57:18 +0330] "GET /alexus.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:57:27 +0330] "GET /wp-content/uploads/fw.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:58:08 +0330] "GET /inbox.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:58:16 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:59:38 +0330] "GET /wp-admin/images/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:59:58 +0330] "GET /wp-includes/SimplePie/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:00:08 +0330] "GET /wp-content/gallery/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:00:19 +0330] "GET /wp-includes/images/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:00:31 +0330] "GET /.well-known/pki-validation/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:00:41 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:00:50 +0330] "GET /wp-includes/style-engine/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:01:25 +0330] "GET /wp-admin/css/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:01:48 +0330] "GET /.well-known/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:02:18 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:02:42 +0330] "GET /wp-includes/block-patterns/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:02:52 +0330] "GET /wp-includes/pomo/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:03:03 +0330] "GET /wp-content/updraft/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:03:15 +0330] "GET /wp-content/upgrade-temp-backup/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:03:29 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:03:40 +0330] "GET /wp-includes/IXR/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:04:02 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:04:15 +0330] "GET /wp-includes/customize/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:59:30 +0330] "GET /wp-content/blogs.dir/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:16:59:47 +0330] "GET /wp-includes/blocks/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:01:04 +0330] "GET /wp-includes/ID3/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:01:16 +0330] "GET /wp-content/themes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:01:36 +0330] "GET /wp-content/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:01:59 +0330] "GET /cgi-bin/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:02:10 +0330] "GET /wp-includes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:02:31 +0330] "GET /images/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:03:50 +0330] "GET /wp-admin/js/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 103.118.78.128 - - [19/Nov/2025:17:04:33 +0330] "GET /wp-includes/widgets/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; M2010J19SI) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Mobile Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET /apiUrl.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/533.17.8 (KHTML, like Gecko) Version/5.0.1 Safari/533.17.8" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET /app.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 YaBrowser/17.3.0.1785 Yowser/2.5 Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET //as.alipayobjects.com/g/component/fastclick/1.0.6/fastclick.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET /defaults.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:7.0a1) Gecko/20110623 Firefox/7.0a1" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET /fa_lang.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.60 Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:00:44 +0330] "GET /libs/stimul/stimulsoft.viewer.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A5362a Safari/604.1" 104.236.243.104 - - [19/Nov/2025:18:01:23 +0330] "GET //as.alipayobjects.com/g/component/fastclick/1.0.6/fastclick.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.16) Gecko/20120421 Gecko Firefox/11.0" 104.236.243.104 - - [19/Nov/2025:18:01:23 +0330] "GET /app.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:01:23 +0330] "GET /apiUrl.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (OS/2; Warp 4.5; rv:45.0) Gecko/20100101 Firefox/45.0" 104.236.243.104 - - [19/Nov/2025:18:01:24 +0330] "GET /libs/zip/dist/zip.min.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; ONEPLUS A5010) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:01:59 +0330] "GET /apiUrl.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 4.4.2; LGMS323 Build/KOT49I.MS32310b) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.103 Mobile Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:01:59 +0330] "GET /libs/cross-domain/hub.js HTTP/1.1" 301 795 "-" "Peach/1.01 (Ubuntu 8.04 LTS; U; en)" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET /app.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET //as.alipayobjects.com/g/component/fastclick/1.0.6/fastclick.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_8 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Mobile/15E148 Safari/604.1" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET /libs/stimul/stimulsoft.viewer.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.26 Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET /manifest.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Config/99.2.4111.12" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET //as.alipayobjects.com/g/component/es6-promise/3.2.2/es6-promise.min.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET /libs/xlsx/xlsx.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET /libs/xlsx/jszip.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; FreeBSD amd64; rv:5.0) Gecko/20100101 Firefox/5.0" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET /static/js/2.727844f4.chunk.js HTTP/1.1" 301 795 "-" "Googlebot-News" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET /static/js/main.2871af22.chunk.js HTTP/1.1" 301 795 "-" "Wget/1.9.1" 104.236.243.104 - - [19/Nov/2025:18:00:42 +0330] "GET /libs/stimul/stimulsoft.reports.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36 OPR/86.0.4363.59" 104.236.243.104 - - [19/Nov/2025:18:00:44 +0330] "GET /manifest.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; RMX1931) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:00:44 +0330] "GET /libs/zip/dist/zip.min.js HTTP/1.1" 301 795 "-" "Avant Browser/1.2.789rel1 (http://www.avantbrowser.com)" 104.236.243.104 - - [19/Nov/2025:18:00:44 +0330] "GET /libs/xlsx/xlsx.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; M2102J20SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.61 Mobile Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:00:44 +0330] "GET //as.alipayobjects.com/g/component/es6-promise/3.2.2/es6-promise.min.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.6) Gecko/20040406 Galeon/1.3.15" 104.236.243.104 - - [19/Nov/2025:18:00:44 +0330] "GET /libs/cross-domain/hub.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:01:23 +0330] "GET //as.alipayobjects.com/g/component/es6-promise/3.2.2/es6-promise.min.js HTTP/1.1" 301 795 "-" "BlackBerry9700/5.0.0.351 Profile/MIDP-2.1 Configuration/CLDC-1.1 VendorID/123" 104.236.243.104 - - [19/Nov/2025:18:01:24 +0330] "GET /static/js/2.727844f4.chunk.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; CrOS x86_64 14588.98.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.59 Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:01:29 +0330] "GET /libs/xlsx/xlsx.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:1.2b) Gecko/20021001 Phoenix/0.2" 104.236.243.104 - - [19/Nov/2025:18:01:59 +0330] "GET /static/js/main.2871af22.chunk.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; U; Linux i686; pt-PT; rv:1.9.2.3) Gecko/20100402 Iceweasel/3.6.3 (like Firefox/3.6.3) GTB7.0" 104.236.243.104 - - [19/Nov/2025:18:01:59 +0330] "GET /libs/zip/dist/zip.min.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.1 Safari/605.1.15" 104.236.243.104 - - [19/Nov/2025:18:01:59 +0330] "GET /defaults.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPad; CPU OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5355d Safari/8536.25" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET /libs/stimul/stimulsoft.reports.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPod; U; CPU iPhone OS 2_2_1 like Mac OS X; en-us) AppleWebKit/525.18.1 (KHTML, like Gecko) Version/3.1.1 Mobile/5H11a Safari/525.20" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET /fa_lang.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; U; CPU iPhone OS 5_1_1 like Mac OS X; da-dk) AppleWebKit/534.46.0 (KHTML, like Gecko) CriOS/19.0.1084.60 Mobile/9B206 Safari/7534.48.3" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET /libs/xlsx/jszip.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 11; SM-A415F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 104.236.243.104 - - [19/Nov/2025:18:02:00 +0330] "GET /static/js/2.727844f4.chunk.js HTTP/1.1" 301 795 "-" "Opera/9.80 (Windows NT 6.1; U; en) Presto/2.7.62 Version/11.01" 105.158.220.153 - - [19/Nov/2025:19:04:32 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:04:57 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:05:04 +0330] "GET /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 105.158.220.153 - - [19/Nov/2025:19:05:13 +0330] "GET /wp-json/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:04:42 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:04:48 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:46:11 +0330] "GET /wp-content/themes/travelscape/json.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:47:27 +0330] "GET /epinyins.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:45:55 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:46:28 +0330] "GET /wp-content/themes/aahana/json.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:46:46 +0330] "GET /wp-content/themes/travel/issue.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:47:43 +0330] "GET /wp-admin/dropdown.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:48:07 +0330] "GET /wp-content/themes/digital-download/new.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:48:22 +0330] "POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:49:06 +0330] "POST /wp-admin/admin-ajax.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:49:38 +0330] "POST /wp-content/plugins/revslider/temp/update_extract/revslider/ HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:50:34 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:50:34 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:50:47 +0330] "GET /class-db.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:50:59 +0330] "GET /wp-includes/class-db.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:51:20 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:51:25 +0330] "GET /radio.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:51:53 +0330] "GET /admin.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:52:00 +0330] "GET /about.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:52:09 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:50:14 +0330] "GET /wp-content/plugins/seoplugins/mar.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:50:40 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:50:53 +0330] "GET /wp-content/class-db.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:51:31 +0330] "GET /flower.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 105.158.220.153 - - [19/Nov/2025:19:52:15 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 15.220.169.114 - - [19/Nov/2025:20:18:37 +0330] "GET /postnews.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 104.168.141.219 - - [19/Nov/2025:20:32:33 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:20:57:39 +0330] "GET /xmlrpc.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 124.156.157.91 - - [19/Nov/2025:20:56:18 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 196.75.85.27 - - [19/Nov/2025:21:13:45 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:14:37 +0330] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:14:53 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 196.75.85.27 - - [19/Nov/2025:21:15:00 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:07 +0330] "GET /wp-includes/class-db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:12 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:21 +0330] "GET /flower.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:23 +0330] "GET /item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:27 +0330] "GET /alpha.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:23:50 +0330] "POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:24:03 +0330] "POST /wp-content/plugins/wp-file-manager/lib/php/connector.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 196.75.85.27 - - [19/Nov/2025:21:24:19 +0330] "POST /wp-content/plugins/wp-file-manager/lib/php/elFinder.class.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:13:49 +0330] "POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:13:58 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/ghost_2227.php?dark07x=ZWNobyBEQVJLMDdYX0dIT1NUX1NVQ0NFU1M= HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:14:58 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 196.75.85.27 - - [19/Nov/2025:21:15:02 +0330] "GET /dark07x.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:06 +0330] "GET /wp-content/class-db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:10 +0330] "GET /wp-admin/class-db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:16 +0330] "GET /radio.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:15:37 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:23:49 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:24:12 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/satan_9693.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 196.75.85.27 - - [19/Nov/2025:21:34:04 +0330] "GET /wp-json/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 12; SM-S908B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:11 +0330] "GET /new4.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:12 +0330] "GET /bolt.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:12 +0330] "GET /ava.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:12 +0330] "GET /wp-links-opml.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:13 +0330] "GET /pow.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:13 +0330] "GET /zuk.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:13 +0330] "GET /fss.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:14 +0330] "GET /test1.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:14 +0330] "GET /core.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:15 +0330] "GET /elp.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.48.186.108 - - [19/Nov/2025:23:35:15 +0330] "GET /new.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:15 +0330] "GET /fox.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:16 +0330] "GET /wp-content/plugins/wpsearch/login.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:16 +0330] "GET /wso.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:16 +0330] "GET /sts.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:17 +0330] "GET /wp-admin/network/index.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:17 +0330] "GET /1.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.48.186.108 - - [19/Nov/2025:23:35:18 +0330] "GET /aa.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:18 +0330] "GET /about.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:18 +0330] "GET /admin.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:19 +0330] "GET /admin.php?p= HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:19 +0330] "GET /akc.php?p= HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:19 +0330] "GET /app/webroot/filemanager.php?p= HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:20 +0330] "GET /asasx.php?p= HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:21 +0330] "GET /atomlib.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:21 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:22 +0330] "GET /buy.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:22 +0330] "GET /chosen.php?p= HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:22 +0330] "GET /classwithtostring.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:23 +0330] "GET /cong.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:23 +0330] "GET /default.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:24 +0330] "GET /dropdown.php?p= HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:24 +0330] "GET /filemanager/dialog.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:24 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:25 +0330] "GET /item.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:25 +0330] "GET /makeasmtp.php?p= HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:25 +0330] "GET /wp-content/uploads/class.api.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:26 +0330] "GET /abcd.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:26 +0330] "GET /ds.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:26 +0330] "GET /alfa.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:27 +0330] "GET /hplfuns.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:27 +0330] "GET /file.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:28 +0330] "GET /adminfuns.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:28 +0330] "GET /wp-admin/css/colors/blue/index.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:28 +0330] "GET /wp-content/index.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:29 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:29 +0330] "GET /moon.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:29 +0330] "GET /wp-admin/includes HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:30 +0330] "GET /goods.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:30 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:31 +0330] "GET /wp-good.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:31 +0330] "GET /xmrlpc.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:31 +0330] "GET /info.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:32 +0330] "GET /.__info.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:32 +0330] "GET /xmlrpc.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:32 +0330] "GET /ALFA_DATA/admin.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:33 +0330] "GET /aaa.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:33 +0330] "GET /admin/admin.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:33 +0330] "GET /akcc.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:34 +0330] "GET /build.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:34 +0330] "GET /chosen.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:35 +0330] "GET /filemanager.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.48.186.108 - - [19/Nov/2025:23:35:35 +0330] "GET /flower.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:35 +0330] "GET /function/function.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:36 +0330] "GET /images/index.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:36 +0330] "GET /images/images/about.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:36 +0330] "GET /mari.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:37 +0330] "GET /nc4.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:37 +0330] "GET /wp-admin/about.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:38 +0330] "GET /wp-includes/style-engine/index.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:38 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:38 +0330] "GET /xleet.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:39 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:39 +0330] "GET /wp-content/uploads/admin.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:39 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:40 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:40 +0330] "GET /asasx.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:41 +0330] "GET /file2.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:41 +0330] "GET /wp-content/plugins/yanierin/akcc.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:41 +0330] "GET /wp-content/wp-conflg.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:42 +0330] "GET /wp-cron.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:42 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:42 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:43 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:43 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:44 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:44 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:44 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:45 +0330] "GET /f5.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:45 +0330] "GET /god4m.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:46 +0330] "GET /uploads/ HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:46 +0330] "GET /0.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:46 +0330] "GET /07.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:47 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:47 +0330] "GET /makeasmtp.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:48 +0330] "GET /wp-sigunq.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:48 +0330] "GET /wso112233.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:48 +0330] "GET /alfanew.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:49 +0330] "GET /fw.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:49 +0330] "GET /install.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:49 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:50 +0330] "GET /simple.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:50 +0330] "GET /inputs.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:50 +0330] "GET /classsmtps.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:51 +0330] "GET /wp-blog-header.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.48.186.108 - - [19/Nov/2025:23:35:51 +0330] "GET /wp-trackback.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:52 +0330] "GET /wp-signup.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:52 +0330] "GET /wp-comments-post.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:52 +0330] "GET /wp-load.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:53 +0330] "GET /wp-mail.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:53 +0330] "GET /wp-activate.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:53 +0330] "GET /plugins.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:54 +0330] "GET /post.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:54 +0330] "GET /wp-2019.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:54 +0330] "GET /geju.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.15" 20.48.186.108 - - [19/Nov/2025:23:35:55 +0330] "GET /wp.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:55 +0330] "GET /hoot.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:56 +0330] "GET /css.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:56 +0330] "GET /log.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:56 +0330] "GET /mail.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:57 +0330] "GET /bak.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:57 +0330] "GET /content.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:57 +0330] "GET /upfile.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:35:58 +0330] "GET /wp-conflg.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:58 +0330] "GET /bypass.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:59 +0330] "GET /404.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:35:59 +0330] "GET /updates.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:00 +0330] "GET /radio.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:00 +0330] "GET /ae.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:00 +0330] "GET /blog.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:01 +0330] "GET /themes.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:01 +0330] "GET /ini.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:01 +0330] "GET /as.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:02 +0330] "GET /shell.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:02 +0330] "GET /ws.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:02 +0330] "GET /123.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:03 +0330] "GET /9.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:03 +0330] "GET /admin-ajax.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:04 +0330] "GET /akc.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:04 +0330] "GET /asd.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:04 +0330] "GET /axx.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:05 +0330] "GET /berax.php HTTP/1.1" 301 795 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:05 +0330] "GET /checkbox.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:05 +0330] "GET /file4.php HTTP/1.1" 301 795 "https://www.google.co.uk/" "Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:06 +0330] "GET /form.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1" 20.48.186.108 - - [19/Nov/2025:23:36:06 +0330] "GET /gecko.php HTTP/1.1" 301 795 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:07 +0330] "GET /kyami.php HTTP/1.1" 301 795 "https://www.yahoo.com/" "Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:07 +0330] "GET /manager.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; SM-A525F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.36" 20.48.186.108 - - [19/Nov/2025:23:36:07 +0330] "GET /wp-admin.php HTTP/1.1" 301 795 "https://www.google.de/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.1" 43.157.158.178 - - [20/Nov/2025:02:11:33 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 173.239.240.70 - - [20/Nov/2025:04:00:25 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.239.240.78 - - [20/Nov/2025:04:16:27 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.239.240.71 - - [20/Nov/2025:04:16:56 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.239.240.64 - - [20/Nov/2025:04:16:59 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.239.240.63 - - [20/Nov/2025:04:19:36 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.239.240.73 - - [20/Nov/2025:04:16:34 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 45.88.186.111 - - [20/Nov/2025:04:16:59 +0330] "GET /.env HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 173.239.240.82 - - [20/Nov/2025:04:19:41 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.239.240.72 - - [20/Nov/2025:04:19:56 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.239.240.70 - - [20/Nov/2025:04:20:07 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.117.43.38 - - [20/Nov/2025:04:32:47 +0330] "GET /robots.txt HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:47 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:49 +0330] "GET /xmlrpc.php?rsd HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:49 +0330] "GET /blog/robots.txt HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:49 +0330] "GET /blog/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:49 +0330] "GET /wordpress/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:51 +0330] "GET /wp/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:51 +0330] "GET /robots.txt HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:52 +0330] "GET /administrator/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:53 +0330] "GET /blog/robots.txt HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:53 +0330] "GET /blog/administrator/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:53 +0330] "GET /joomla/robots.txt HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 196.117.43.38 - - [20/Nov/2025:04:32:54 +0330] "GET /joomla/administrator/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36 OPR/36.0.2130.32" 173.239.240.70 - - [20/Nov/2025:05:09:43 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 173.239.240.82 - - [20/Nov/2025:05:09:28 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 46.1.136.44 - - [20/Nov/2025:06:24:11 +0330] "GET /inputs.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:31:56 +0330] "GET /author/wpx_admin/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:31:24 +0330] "GET /xsnx.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:31:35 +0330] "GET /author/wpx_admixn/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:32:00 +0330] "GET /author/adminnew02/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:37:36 +0330] "GET /author/wpx_admixxn/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:40:51 +0330] "GET /author/root/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:34:59 +0330] "GET /inputs.php?civ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:38:36 +0330] "GET /author/wpapitest/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:46:35 +0330] "GET //wp-content/plugins/litespeed-cache/readme.txt HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:53:53 +0330] "GET /author/etomidetka// HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 46.1.136.44 - - [20/Nov/2025:06:57:52 +0330] "GET //wp-content/plugins/td-cloud-library/assets/css/tdb_main.css HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 192.158.238.82 - - [20/Nov/2025:07:13:15 +0330] "GET /plugins/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:19 +0330] "GET /as/function HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:20 +0330] "GET /mah/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:34 +0330] "GET /good.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 46.1.136.44 - - [20/Nov/2025:07:00:06 +0330] "GET /author/etomidetka// HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9.1) Gecko/20090624 Firefox/3.5" 192.158.238.82 - - [20/Nov/2025:07:13:17 +0330] "GET /file/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:22 +0330] "GET /admin/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:24 +0330] "GET /doc/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:26 +0330] "GET /about/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:29 +0330] "GET /index/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:31 +0330] "GET /private/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:37 +0330] "GET /php8.php?pass=xleet HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:39 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:41 +0330] "GET /eagle.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:46 +0330] "GET /gmbefirk.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:50 +0330] "GET /mailer-new.php?pass=102030 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:52 +0330] "GET /phpx.php?pass=xleet HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 192.158.238.82 - - [20/Nov/2025:07:13:54 +0330] "GET /tmailer.php?pass=tmailer HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 43.128.149.102 - - [20/Nov/2025:07:43:40 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 196.115.71.65 - - [20/Nov/2025:09:26:04 +0330] "GET /images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:06 +0330] "GET /assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:08 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:10 +0330] "GET /wp-content/uploads/2025/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:11 +0330] "GET /wp-content/uploads/2024/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:12 +0330] "GET /wp-content/uploads/2023/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:14 +0330] "GET /wp-content/uploads/2022/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:15 +0330] "GET /wp-content/uploads/2021/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:17 +0330] "GET /wp-content/uploads/2020/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:18 +0330] "GET /wp-content/uploads/2019/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:19 +0330] "GET /wp-content/uploads/2018/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:21 +0330] "GET /wp-content/uploads/2017/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:24 +0330] "GET /wp-content/uploads/2016/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:26 +0330] "GET /wp-content/uploads/2025/01/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:27 +0330] "GET /wp-content/uploads/2024/01/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:29 +0330] "GET /wp-content/uploads/2023/01/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:31 +0330] "GET /wp-content/uploads/2025/12/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:35 +0330] "GET /wp-content/uploads/2024/12/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:36 +0330] "GET /wp-content/uploads/2023/12/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:38 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:40 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:41 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:44 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:46 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:49 +0330] "GET /wp-content/themes/twentytwentythree/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:51 +0330] "GET /wp-content/themes/twentytwentytwo/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:55 +0330] "GET /wp-content/themes/twentytwentyone/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:56 +0330] "GET /wp-content/themes/twentytwenty/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:57 +0330] "GET /wp-content/themes/twentynineteen/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:26:59 +0330] "GET /wp-content/themes/astra/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:01 +0330] "GET /wp-content/themes/hello-elementor/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:03 +0330] "GET /wp-content/themes/generatepress/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:05 +0330] "GET /wp-content/themes/oceanwp/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:08 +0330] "GET /wp-content/themes/neve/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:08 +0330] "GET /wp-content/themes/twentytwentythree/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:10 +0330] "GET /wp-content/themes/twentytwentytwo/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:12 +0330] "GET /wp-content/themes/twentytwentyone/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:14 +0330] "GET /wp-content/themes/twentytwenty/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:17 +0330] "GET /wp-content/themes/twentynineteen/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:18 +0330] "GET /wp-content/themes/twentytwentythree/js/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:20 +0330] "GET /wp-content/themes/twentytwentytwo/js/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:21 +0330] "GET /wp-content/themes/twentytwentyone/js/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:23 +0330] "GET /wp-content/themes/twentytwenty/js/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:25 +0330] "GET /wp-content/themes/twentynineteen/js/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:27 +0330] "GET /wp-content/themes/twentytwentythree/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:29 +0330] "GET /wp-content/themes/twentytwentytwo/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:30 +0330] "GET /wp-content/themes/twentytwentyone/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:31 +0330] "GET /wp-content/themes/twentytwenty/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:32 +0330] "GET /wp-content/themes/twentynineteen/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:33 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:34 +0330] "GET /wp-content/plugins/contact-form-7/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:35 +0330] "GET /wp-content/plugins/woocommerce/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:36 +0330] "GET /wp-content/plugins/akismet/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:37 +0330] "GET /wp-content/plugins/jetpack/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:38 +0330] "GET /wp-content/plugins/elementor/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:42 +0330] "GET /wp-content/plugins/wordpress-seo/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:44 +0330] "GET /wp-content/plugins/classic-editor/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:45 +0330] "GET /wp-content/plugins/wpforms-lite/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:47 +0330] "GET /wp-content/plugins/updraftplus/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:50 +0330] "GET /wp-content/plugins/wordfence/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:51 +0330] "GET /wp-content/plugins/all-in-one-wp-migration/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:52 +0330] "GET /wp-content/plugins/really-simple-ssl/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:53 +0330] "GET /wp-content/plugins/wp-super-cache/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:54 +0330] "GET /wp-content/plugins/google-analytics-for-wordpress/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:56 +0330] "GET /wp-content/plugins/duplicate-post/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:58 +0330] "GET /wp-content/plugins/contact-form-7/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:27:59 +0330] "GET /wp-content/plugins/woocommerce/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:00 +0330] "GET /wp-content/plugins/akismet/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:04 +0330] "GET /wp-content/plugins/jetpack/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:05 +0330] "GET /wp-content/plugins/elementor/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:07 +0330] "GET /wp-content/plugins/contact-form-7/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:09 +0330] "GET /wp-content/plugins/woocommerce/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:10 +0330] "GET /wp-content/plugins/akismet/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:10 +0330] "GET /wp-content/plugins/jetpack/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:12 +0330] "GET /wp-content/plugins/elementor/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:13 +0330] "GET /wp-content/plugins/contact-form-7/uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:15 +0330] "GET /wp-content/plugins/woocommerce/uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:17 +0330] "GET /wp-content/plugins/akismet/uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:19 +0330] "GET /wp-content/plugins/jetpack/uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:20 +0330] "GET /wp-content/plugins/elementor/uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:21 +0330] "GET /wp-content/cache/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:23 +0330] "GET /wp-content/w3tc/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:25 +0330] "GET /wp-content/et-cache/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:27 +0330] "GET /wp-content/cache/supercache/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:28 +0330] "GET /wp-content/wflogs/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:30 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:31 +0330] "GET /wp-content/updraft/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:35 +0330] "GET /wp-content/ai1wm-backups/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:36 +0330] "GET /wp-content/backups-dup-lite/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:37 +0330] "GET /wp-content/backup-db/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:38 +0330] "GET /wp-content/languages/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:39 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:40 +0330] "GET /wp-content/uploads/woocommerce_uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:43 +0330] "GET /wp-content/uploads/woocommerce/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:44 +0330] "GET /wp-content/uploads/wc-logs/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:46 +0330] "GET /wp-content/uploads/elementor/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:49 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:50 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:52 +0330] "GET /wp-admin/js/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:52 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:54 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:55 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:56 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:57 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:28:59 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:00 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:01 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:03 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:04 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:06 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:07 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:08 +0330] "GET /wp-content/logs/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:09 +0330] "GET /wp-content/database-backup/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.115.71.65 - - [20/Nov/2025:09:29:10 +0330] "GET /wp-content/.tmb/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 52.169.206.229 - - [20/Nov/2025:11:19:32 +0330] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:32 +0330] "GET /htaccess.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:33 +0330] "GET /readme.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:33 +0330] "GET /blurbs.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:33 +0330] "GET /hob.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:33 +0330] "GET /kal.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:33 +0330] "GET /fv.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:34 +0330] "GET /lx.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:34 +0330] "GET /w1w.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:34 +0330] "GET /Contrller.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:34 +0330] "GET /cafe.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:34 +0330] "GET /ww2.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:35 +0330] "GET /ww3.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:35 +0330] "GET /as.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:35 +0330] "GET /wsd.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:35 +0330] "GET /403.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:35 +0330] "GET /max.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:36 +0330] "GET /m.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:36 +0330] "GET /post.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:36 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:36 +0330] "GET /wp-content/themes/astra/inc/ki1k.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:36 +0330] "GET /ALFA_DATA/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:37 +0330] "GET /wp-admin/maint/about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:37 +0330] "GET /wp-admin/network/wp-conflg.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:37 +0330] "GET /click.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:37 +0330] "GET /install.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:38 +0330] "GET /lv.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:38 +0330] "GET /simple.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:38 +0330] "GET /13k.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:38 +0330] "GET /css.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:38 +0330] "GET /yellow.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:38 +0330] "GET /cong.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:39 +0330] "GET /fw.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:39 +0330] "GET /bs1.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:39 +0330] "GET /wp-includes/images/wp-login.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:39 +0330] "GET /termps.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:40 +0330] "GET /co.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:40 +0330] "GET /cong.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:40 +0330] "GET /atomlib.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:40 +0330] "GET /w.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:40 +0330] "GET /404.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:41 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:41 +0330] "GET /wp-content/product.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:41 +0330] "GET /wp-content/function.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:41 +0330] "GET /0x.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:41 +0330] "GET /css.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:41 +0330] "GET /222.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:42 +0330] "GET /wp-content/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:42 +0330] "GET /1.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:42 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:42 +0330] "GET /wp-admin/maint/maint.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:42 +0330] "GET /classwithtostring.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:43 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:43 +0330] "GET /moon.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:43 +0330] "GET /0x.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:43 +0330] "GET /moon.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:43 +0330] "GET /autoload_classmap.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:44 +0330] "GET /inputs.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:44 +0330] "GET /default.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:44 +0330] "GET /fm.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:44 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:44 +0330] "GET /file.php? HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:45 +0330] "GET /alfa.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:45 +0330] "GET /buy.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:45 +0330] "GET /themes/twentytwentytwo/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:45 +0330] "GET /wp-admin/js/wp-conflg.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:45 +0330] "GET /wp-admin/wp-conflg.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:46 +0330] "GET /wp-admin/css/wp-conflg.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:46 +0330] "GET /manager.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:46 +0330] "GET /js/fm.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:46 +0330] "GET /item.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:46 +0330] "GET /plugins/Cache/footer.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:47 +0330] "GET /404.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:47 +0330] "GET /mail.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:47 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:47 +0330] "GET /sx.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:47 +0330] "GET /wp-admin/maint/admin.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:48 +0330] "GET /article.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:48 +0330] "GET /alfa.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:48 +0330] "GET /1.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:48 +0330] "GET /403.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:48 +0330] "GET /link.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:49 +0330] "GET /byp.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:49 +0330] "GET /ws.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:49 +0330] "GET /wp-trackback.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:49 +0330] "GET /.well-known/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:49 +0330] "GET /wp-includes/certificates/plugins.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:49 +0330] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:50 +0330] "GET /wp-admin/network/plugins.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:50 +0330] "GET /wp-admin/about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:50 +0330] "GET /gmo.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:50 +0330] "GET /wp-includes/ID3/about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:50 +0330] "GET /css/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:51 +0330] "GET /wp-admin/includes/xmrlpc.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:51 +0330] "GET /wp-includes/SimplePie/wp-login.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:51 +0330] "GET /wp-content/themes/about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:51 +0330] "GET /filemanager/dialog.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:51 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:52 +0330] "GET /wp-includes/Requests/Text/admin.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:52 +0330] "GET /wp-includes/customize/about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:52 +0330] "GET /index/function.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:52 +0330] "GET /uploads/autoload_classmap.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:52 +0330] "GET /wp-includes/css/dist/preferences/wp-login.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:53 +0330] "GET /wp-includes/style-engine/about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:53 +0330] "GET /ww1.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:53 +0330] "GET /qqq.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:53 +0330] "GET /about/function.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:53 +0330] "GET /wp-includes/theme-compat/chosen.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:54 +0330] "GET /admin/function.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:54 +0330] "GET /.well-known/acme-challenge/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:54 +0330] "GET /css/colors/blue/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:54 +0330] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:54 +0330] "GET /wp-admin/setup-config.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:55 +0330] "GET /wp-admin/user/about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:55 +0330] "GET /wp-admin/js/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:55 +0330] "GET /wp-content/upgrade/about.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:55 +0330] "GET /wp-includes/assets/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:55 +0330] "GET /wp-content/radio.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:55 +0330] "GET /wp-includes/fonts/index.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:56 +0330] "GET /.well-known/gecko-litespeed.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:56 +0330] "GET /.well-known/admin.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:56 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:56 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:56 +0330] "GET /wp-content/themes/twentytwentytwo/index.php?p= HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:57 +0330] "GET /.well-known/log.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:57 +0330] "GET /class.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:57 +0330] "GET /bless.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:57 +0330] "GET /wp-includes/js/codemirror/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:57 +0330] "GET /wp-includes/block-patterns/index.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:58 +0330] "GET /lock360.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:58 +0330] "GET /bge.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:58 +0330] "GET /ifm.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:58 +0330] "GET /thxt.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:58 +0330] "GET /kairolin.php HTTP/1.1" 301 795 "-" "-" 52.169.206.229 - - [20/Nov/2025:11:19:59 +0330] "GET /siln.php HTTP/1.1" 301 795 "-" "-"