Файловый менеджер - Редактировать - /usr/local/apache/domlogs/freeclou/app.optimyar.com
Назад
89.131.59.73 - - [05/Nov/2025:15:48:24 +0330] "GET //wp-admin/css/colors/blue/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:15:49:50 +0330] "GET //wp-includes/images/crystal/wp-work.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:15:51:05 +0330] "GET //wp-admin/css/colors/blue/wp-work.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:15:54:15 +0330] "GET //BDKR28WP.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Mobile/15E148 Safari/604.1" 194.165.16.8 - - [05/Nov/2025:15:54:44 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0" 89.131.59.73 - - [05/Nov/2025:15:55:21 +0330] "GET //comment.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Mobile/15E148 Safari/604.1" 196.217.135.31 - - [05/Nov/2025:15:56:31 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:32 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:32 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:37 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:38 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:46 +0330] "GET /wp-content/themes/classic/inc/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:48 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:51 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:55 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:55 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 89.131.59.73 - - [05/Nov/2025:15:56:27 +0330] "GET //content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 196.217.135.31 - - [05/Nov/2025:15:56:30 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:34 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:34 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:35 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:46 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:53 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:54 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:57 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:56:58 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:15 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:20 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:21 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:21 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:29 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:30 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:32 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:33 +0330] "GET /uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:34 +0330] "GET /upload/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:36 +0330] "GET /admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:37 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:38 +0330] "GET /admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:40 +0330] "GET /assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:44 +0330] "GET /assets/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:46 +0330] "GET /Public/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:50 +0330] "GET /vendor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:55 +0330] "GET /Site/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:00 +0330] "GET /template/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:10 +0330] "GET /admin/editor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:14 +0330] "GET /include/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:37 +0330] "GET /plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:00 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:19 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 89.131.59.73 - - [05/Nov/2025:15:57:36 +0330] "GET //.well-known/info.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 196.217.135.31 - - [05/Nov/2025:15:57:39 +0330] "GET /images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:41 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:43 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:51 +0330] "GET /local/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:52 +0330] "GET /modules/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:57:56 +0330] "GET /system/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:01 +0330] "GET /shop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:02 +0330] "GET /files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:21 +0330] "GET /Assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:38 +0330] "GET /php/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:41 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:42 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:43 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:46 +0330] "GET /wp-includes/SimplePie/Cache/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:48 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:50 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:51 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 89.131.59.73 - - [05/Nov/2025:15:58:55 +0330] "GET //.well-known/gecko-litespeed.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 196.217.135.31 - - [05/Nov/2025:15:58:59 +0330] "GET /wp-includes/Requests/Cookie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:00 +0330] "GET /wp-includes/Requests/Proxy/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:01 +0330] "GET /wp-includes/Requests/Response/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:02 +0330] "GET /wp-includes/Requests/Utility/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:04 +0330] "GET /wp-includes/Requests/Exception/HTTP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:07 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:08 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:11 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:12 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:39 +0330] "GET /wp-includes/assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:40 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:44 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:45 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:46 +0330] "GET /wp-includes/SimplePie/Content/Type/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:58:49 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:01 +0330] "GET /wp-includes/Requests/Transport/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:03 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:05 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:09 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:10 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:12 +0330] "GET /wp-includes/Requests/Exception/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:13 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:17 +0330] "GET /wp-includes/Text/Diff/Engine/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:19 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:15 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:19 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:30 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:31 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:36 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:38 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:40 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:41 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:42 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:43 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:45 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:46 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:46 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:47 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:49 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:21 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:22 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:23 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:24 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:25 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:25 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:26 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:32 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:33 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:34 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:37 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:41 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:53 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:54 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:05 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:50 +0330] "GET /components/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:15:59:51 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:01 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:02 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:04 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 89.131.59.73 - - [05/Nov/2025:16:00:08 +0330] "GET //wp-admin/includes/alfa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 196.217.135.31 - - [05/Nov/2025:16:00:11 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:12 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:22 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:23 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:25 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 89.131.59.73 - - [05/Nov/2025:16:01:15 +0330] "GET //wp-admin/alfa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:03:11 +0330] "GET //alfa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:04:04 +0330] "GET /ss.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:04:54 +0330] "GET //wp-admin/css/BDKR28_otbo7jmd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:05:43 +0330] "GET //wp-admin/css/0xbp3dip.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 196.217.135.31 - - [05/Nov/2025:16:00:06 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:07 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:14 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:14 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:16:00:24 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 194.165.16.8 - - [05/Nov/2025:16:02:05 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" 89.131.59.73 - - [05/Nov/2025:16:07:47 +0330] "GET //wp-admin/css/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:10:36 +0330] "GET //wp-admin/css/BDKR28_qe5wsbkm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:10:45 +0330] "GET //wp-admin/css/ggg06s7m.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 48.218.65.210 - - [05/Nov/2025:16:27:34 +0330] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:36 +0330] "GET /shoha.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:36 +0330] "GET /kaza.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:37 +0330] "GET /wsd.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:37 +0330] "GET /gifclass4.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:38 +0330] "GET /info.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:39 +0330] "GET /333.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:41 +0330] "GET /cfile.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:42 +0330] "GET /bless3.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:43 +0330] "GET /bless.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:43 +0330] "GET /doti.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:44 +0330] "GET /031.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:44 +0330] "GET /wfile.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:45 +0330] "GET /lala.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:46 +0330] "GET /gmo.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:46 +0330] "GET /he.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:47 +0330] "GET /plss3.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:47 +0330] "GET /ton.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:48 +0330] "GET /nfile.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:48 +0330] "GET /ffile.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:49 +0330] "GET /file18.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:50 +0330] "GET /file21.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:50 +0330] "GET /yellow.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:51 +0330] "GET /file1.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:51 +0330] "GET /geck.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:52 +0330] "GET /file4.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:52 +0330] "GET /file88.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:53 +0330] "GET /111.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:54 +0330] "GET /size.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:54 +0330] "GET /bolt.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:55 +0330] "GET /file8.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:56 +0330] "GET /file2.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:56 +0330] "GET /vee.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:57 +0330] "GET /a2.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:57 +0330] "GET /mlex.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:58 +0330] "GET /030.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:59 +0330] "GET /haa.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:27:59 +0330] "GET /xsox.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:00 +0330] "GET /classgoto24.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:01 +0330] "GET /inde.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:01 +0330] "GET /akk.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:02 +0330] "GET /alpa.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:02 +0330] "GET /finny.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:03 +0330] "GET /file15.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:04 +0330] "GET /0x0x.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:04 +0330] "GET /2clas.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:05 +0330] "GET /file9.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:05 +0330] "GET /aaa.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:06 +0330] "GET /ilex.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:06 +0330] "GET /tor.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:07 +0330] "GET /klex.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:07 +0330] "GET /shell1.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:08 +0330] "GET /sec.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:09 +0330] "GET /filesss.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:09 +0330] "GET /ea.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:10 +0330] "GET /gi.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:10 +0330] "GET /10.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:11 +0330] "GET /11.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:12 +0330] "GET /12.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:12 +0330] "GET /13.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:13 +0330] "GET /hi.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:13 +0330] "GET /v.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:14 +0330] "GET /ar.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:15 +0330] "GET /article.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:15 +0330] "GET /install.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:16 +0330] "GET /1.php HTTP/1.1" 301 795 "-" "-" 89.131.59.73 - - [05/Nov/2025:16:06:43 +0330] "GET //wp-admin/css/BDKR.txt HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.6 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:06:52 +0330] "GET //wp-admin/css/1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:11:35 +0330] "GET //wp-admin/css/anan.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:12:42 +0330] "GET /wp-admin/maint/rk1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:14:02 +0330] "GET /wp-admin/rk1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:14:43 +0330] "GET //rk1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 89.131.59.73 - - [05/Nov/2025:16:15:21 +0330] "GET //wp-admin/includes/rk2.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Mobile/15E148 Safari/604.1" 43.153.12.58 - - [05/Nov/2025:16:53:25 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 48.218.65.210 - - [05/Nov/2025:16:28:16 +0330] "GET /bak.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:17 +0330] "GET /ini.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:18 +0330] "GET /mail.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:18 +0330] "GET /dlu.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:19 +0330] "GET /zde.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:19 +0330] "GET /ifm.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:20 +0330] "GET /redi.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:21 +0330] "GET /fns.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:21 +0330] "GET /pent.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:22 +0330] "GET /wsx.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:22 +0330] "GET /r79.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:23 +0330] "GET /mpxct.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:23 +0330] "GET /x3.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:24 +0330] "GET /wan.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:25 +0330] "GET /iov.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:25 +0330] "GET /ouh.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:26 +0330] "GET /asgtt.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:27 +0330] "GET /image.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:28 +0330] "GET /wok.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:28 +0330] "GET /alexus.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:29 +0330] "GET /sadis.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:30 +0330] "GET /admir.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:30 +0330] "GET /file52.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:31 +0330] "GET /133.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:32 +0330] "GET /x0.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:32 +0330] "GET /wsr2.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:33 +0330] "GET /wolv.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:33 +0330] "GET /av.php.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:34 +0330] "GET /pn.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:34 +0330] "GET /sa.php7 HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:35 +0330] "GET /shellv3.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:36 +0330] "GET /sts.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:36 +0330] "GET /villain.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:37 +0330] "GET /shell_wso.php7 HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:38 +0330] "GET /red.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:38 +0330] "GET /lupo.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:39 +0330] "GET /jhdnZ.php HTTP/1.1" 301 795 "-" "-" 48.218.65.210 - - [05/Nov/2025:16:28:39 +0330] "GET /gh.php HTTP/1.1" 301 795 "-" "-" 194.165.16.8 - - [05/Nov/2025:16:54:27 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0" 194.165.16.8 - - [05/Nov/2025:17:36:02 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0" 196.217.135.31 - - [05/Nov/2025:18:47:30 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:49:11 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:50:25 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:50:27 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:50:28 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:08 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:58 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:53:06 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:53:20 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:53:30 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:53:54 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:54:03 +0330] "GET /xl2023x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:55:32 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:55:33 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:55:41 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:55:52 +0330] "GET /wp-content/plugins/hanau/akc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:06 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:09 +0330] "GET /file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:09 +0330] "GET /wp-content/akp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:14 +0330] "GET /wp-content/plugins/hanau/akc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:15 +0330] "GET /aw.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:22 +0330] "GET /wp-content/plugins/geu/geu.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:38 +0330] "GET /wp-content/plugins/deu/ms.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:39 +0330] "GET /wp-content/plugins/view-ad/ms.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:48 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:52:50 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:53:17 +0330] "GET /504.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:53:22 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:54:05 +0330] "GET /xxl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:54:20 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:55:49 +0330] "GET /file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:55:50 +0330] "GET /wp-content/akp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:00:13 +0330] "GET /chosen.php?p= HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:00:23 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:00:27 +0330] "GET /wp-includes/Text/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:01:36 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:02:43 +0330] "GET /xl2023x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:02:44 +0330] "GET /xxl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:03:25 +0330] "GET /wp-includes/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:18:59:30 +0330] "GET /smtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 196.217.135.31 - - [05/Nov/2025:19:00:22 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:00:23 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:02:28 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:02:41 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:02:45 +0330] "GET /x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:02:47 +0330] "GET /xl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:02:51 +0330] "GET /wp-admin/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:05:33 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:08:53 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:08:54 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:08:55 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:08:59 +0330] "GET /wp-includes/Text/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:13:25 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:20:45 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:21:02 +0330] "GET /wp-content/themes/gaukingo/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:21:02 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:21:04 +0330] "GET /wp-content/plugins/ioptimizations/IOptimizes.php?hamlorszd HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:01 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:20:45 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:20:46 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:21:03 +0330] "GET /wp-content/plugins/ioptimization/IOptimize.php?rchk HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:21:07 +0330] "GET /wp-content/uploads/wp_live_chat/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:00 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:05 +0330] "GET /cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:21 +0330] "GET /img/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:04 +0330] "GET /wp-admin/network/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:16 +0330] "GET /cgi-bin/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:20 +0330] "GET /css/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:21 +0330] "GET /wp-admin/user/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:31:24 +0330] "GET /wp-admin/css/colors/coffee/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:36 +0330] "GET /wp-admin/network/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:40 +0330] "GET /cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:43 +0330] "GET /css/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:52 +0330] "GET /img/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:55 +0330] "GET /wp-admin/css/colors/coffee/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:56 +0330] "GET /wp-admin/images/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:04 +0330] "GET /wp-admin/js/widgets/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:04 +0330] "GET /wp-admin/css/colors/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:47 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:48 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:57 +0330] "GET /wp-content/plugins/ioptimization/IOptimize.php?rchk HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:05 +0330] "GET /wp-content/plugins/ioptimizations/IOptimizes.php?hamlorszd HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:08 +0330] "GET /wp-content/uploads/wp_live_chat/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:17 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/a57bze8931.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:33 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:35 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:41 +0330] "GET /cgi-bin/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:41:50 +0330] "GET /wp-admin/user/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:00 +0330] "GET /images/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:46 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:56 +0330] "GET /wp-content/themes/gaukingo/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:42:56 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:27 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:35 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:36 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:46 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/a57bze8931.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:55 +0330] "GET /wp-content/plugins/formcraft/file-upload/server/php/files/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:58 +0330] "GET /wp-content/plugins/formcraft/file-upload/server/php/files/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:59 +0330] "GET /wp-content/plugins/ioptimization/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:02 +0330] "GET /wp-content/plugins/ioptimization/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:04 +0330] "GET /wp-content/plugins/ioptimization/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:05 +0330] "GET /wp-content/plugins/ioptimization/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:05 +0330] "GET /wp-content/plugins/apikey/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:06 +0330] "GET /wp-content/plugins/apikey/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:07 +0330] "GET /wp-content/plugins/apikey/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:16 +0330] "GET /wp-content/plugins/apikey/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:20 +0330] "GET /wp-content/plugins/ioptimizations/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:20 +0330] "GET /wp-content/plugins/ioptimizations/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:22 +0330] "GET /wp-content/plugins/ioptimizations/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:24 +0330] "GET /abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:25 +0330] "GET /abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:17 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:19 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:27 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:37 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:54 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:56 +0330] "GET /wp-content/plugins/formcraft/file-upload/server/php/files/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:43:57 +0330] "GET /wp-content/plugins/formcraft/file-upload/server/php/files/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:24 +0330] "GET /wp-content/plugins/ioptimizations/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:27 +0330] "GET /wp-content/plugins/dzs-zoomsounds/king HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:28 +0330] "GET /wp-content/plugins/dzs-zoomsounds/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:34 +0330] "GET /xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:39 +0330] "GET /a57bze8931.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:27 +0330] "GET /wp-content/plugins/dzs-zoomsounds/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:32 +0330] "GET /wp-content/plugins/dzs-zoomsounds/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:19:44:38 +0330] "GET /king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:09 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:12 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:13 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:17 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:17 +0330] "GET /wp-content/themes/classic/inc/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:18 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:20 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:21 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:22 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:23 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:24 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:25 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:26 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:28 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:29 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:07 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:08 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:10 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:13 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:16 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:19 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:23 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:31 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:32 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:35 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:37 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:40 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:41 +0330] "GET /admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:42 +0330] "GET /images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:48 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:33 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:36 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:38 +0330] "GET /uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:38 +0330] "GET /upload/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:39 +0330] "GET /admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:43 +0330] "GET /assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:47 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:49 +0330] "GET /assets/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:50 +0330] "GET /Public/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:52 +0330] "GET /local/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:57 +0330] "GET /system/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:59 +0330] "GET /template/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:03 +0330] "GET /include/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:04 +0330] "GET /Assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:09 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:52 +0330] "GET /vendor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:53 +0330] "GET /modules/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:20:54 +0330] "GET /Site/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:01 +0330] "GET /shop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:01 +0330] "GET /files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:02 +0330] "GET /admin/editor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:05 +0330] "GET /images/stories/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:07 +0330] "GET /plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:07 +0330] "GET /php/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:08 +0330] "GET /wp-includes/assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:10 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:10 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:11 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:14 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:18 +0330] "GET /wp-includes/SimplePie/Cache/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:20 +0330] "GET /wp-includes/SimplePie/Content/Type/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:21 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:26 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:28 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:37 +0330] "GET /wp-includes/Requests/Response/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:39 +0330] "GET /wp-includes/Requests/Transport/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:40 +0330] "GET /wp-includes/Requests/Utility/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:41 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:44 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:45 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:12 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:22 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:28 +0330] "GET /wp-includes/Requests/Cookie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:29 +0330] "GET /wp-includes/Requests/Proxy/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:42 +0330] "GET /wp-includes/Requests/Exception/HTTP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:43 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:48 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:05 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:16 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:17 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:17 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:21 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:23 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:54 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:57 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:45 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:21:47 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:07 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:11 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:13 +0330] "GET /wp-includes/Text/Diff/Engine/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:14 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:14 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:15 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:26 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:27 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:22:35 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:23:14 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:23:33 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:23:34 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:23:36 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:23:14 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:23:38 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:23:53 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:23:54 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:00 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:02 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:07 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:08 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:09 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:10 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:11 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:13 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:24 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:25 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:26 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:32 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:03 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:04 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:05 +0330] "GET /components/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:06 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:12 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:14 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:15 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:16 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:27 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:20:24:39 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [05/Nov/2025:20:53:22 +0330] "POST /wp-plain.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [05/Nov/2025:20:53:22 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 45.80.158.88 - - [05/Nov/2025:20:53:22 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [05/Nov/2025:20:53:22 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [05/Nov/2025:20:53:22 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [05/Nov/2025:20:53:23 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 141.98.11.16 - - [05/Nov/2025:21:36:48 +0330] "GET /postnews.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:30 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:32 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:34 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:35 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:37 +0330] "GET /wp-content/themes/classic/inc/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:38 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:39 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:40 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:41 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:42 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:44 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:49 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:50 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:51 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:52 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:29 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:31 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:33 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:36 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:36 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:42 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:43 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:45 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:51 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:53 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:54 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:55 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:02 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:02 +0330] "GET /admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:03 +0330] "GET /images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:56 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:13:58 +0330] "GET /uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:00 +0330] "GET /upload/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:01 +0330] "GET /admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:08 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:10 +0330] "GET /Public/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:11 +0330] "GET /vendor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:12 +0330] "GET /modules/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:13 +0330] "GET /Site/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:14 +0330] "GET /system/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:15 +0330] "GET /template/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:18 +0330] "GET /files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:20 +0330] "GET /include/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:21 +0330] "GET /Assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:21 +0330] "GET /images/stories/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:22 +0330] "GET /plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:04 +0330] "GET /assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:06 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:09 +0330] "GET /assets/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:12 +0330] "GET /local/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:16 +0330] "GET /shop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:19 +0330] "GET /admin/editor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:25 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:27 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:30 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:32 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:32 +0330] "GET /wp-includes/SimplePie/Cache/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:33 +0330] "GET /wp-includes/SimplePie/Content/Type/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:37 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:38 +0330] "GET /wp-includes/Requests/Cookie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:40 +0330] "GET /wp-includes/Requests/Transport/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:23 +0330] "GET /php/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:24 +0330] "GET /wp-includes/assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:28 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:29 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:34 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:35 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:36 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:38 +0330] "GET /wp-includes/Requests/Proxy/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:39 +0330] "GET /wp-includes/Requests/Response/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:42 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:44 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:46 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:50 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:51 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:51 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:41 +0330] "GET /wp-includes/Requests/Utility/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:43 +0330] "GET /wp-includes/Requests/Exception/HTTP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:47 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:55 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:56 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:57 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:59 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:00 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:07 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:13 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:14 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:16 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:17 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:18 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:20 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:54 +0330] "GET /wp-includes/Requests/Exception/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:58 +0330] "GET /wp-includes/Text/Diff/Engine/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:14:59 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:01 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:02 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:08 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:12 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:13 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:15 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:19 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:20 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:22 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:23 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:25 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:26 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:27 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:28 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:36 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:37 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:42 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:43 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:46 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:47 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:21 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:24 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:25 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:29 +0330] "GET /components/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:30 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:31 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:33 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:34 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:35 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:37 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:39 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:40 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:41 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:44 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 196.217.135.31 - - [05/Nov/2025:22:15:45 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 43.167.241.46 - - [05/Nov/2025:22:24:24 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 172.93.148.172 - - [05/Nov/2025:23:49:39 +0330] "GET /uploaded_script.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:49:48 +0330] "GET /1mage.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:49:52 +0330] "GET /sid.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:04 +0330] "GET /go.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:04 +0330] "GET /wp-content/plugins/wordpress-seo/rk1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:11 +0330] "GET /wp-content/plugins/zgdsfagck/rk2.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:17 +0330] "GET /wp-admin/css/colors/ocean/Module.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:26 +0330] "GET /erros_run.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:31 +0330] "GET /xt/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:39 +0330] "GET /xt.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:40 +0330] "GET /wp-class.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:46 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:51:24 +0330] "GET /randkeyword.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:51:30 +0330] "GET /flower.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:51:35 +0330] "GET /item.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:51:42 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:03 +0330] "GET /sim.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:03 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:11 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:15 +0330] "GET /edit.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:23 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:24 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:34 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:44 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:49 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:52:54 +0330] "GET /wp-includes/widgets/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:06 +0330] "GET /wp-content/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:16 +0330] "GET /wp-includes/images/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:20 +0330] "GET /wp-includes/Text/Diff/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:25 +0330] "GET /wp-admin/network/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:31 +0330] "GET /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:34 +0330] "GET /wp-content/cong.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:42 +0330] "GET /uploads/k69834253_index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:48 +0330] "GET /wp-content/plugins/rsquaaj/index4.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:53:52 +0330] "GET /xleetshell.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:01 +0330] "GET /wp-admin/includes/xleet-shell.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:05 +0330] "GET /xlt.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:20 +0330] "GET /templates/beez5/mar.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:30 +0330] "GET /wp-content/plugins/xt/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:40 +0330] "GET /wp-content/xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:45 +0330] "GET /wp-admin/xleet-shell.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:53 +0330] "GET /wp-includes/css/css.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:57 +0330] "GET /wp-includes/fonts/css.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:54:59 +0330] "GET /wp-content/uploads/options-writing.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:04 +0330] "GET /wp-content/updates.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:09 +0330] "GET /wp-content/plugins/ango/sett.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:16 +0330] "GET /wp-content/plugins/beast3x/3xup.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:22 +0330] "GET /sellex.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:25 +0330] "GET /wp-admin/maint/wp-login.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:30 +0330] "GET /shell20211028.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:45 +0330] "GET /wp-content/upgrade-functions.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:50 +0330] "GET /wp-content/plugins/revslider/includes/external/page/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:55:55 +0330] "GET /wp-content/plugins/Cache/Cache.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:56:13 +0330] "GET /wp-config-sample.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:56:16 +0330] "GET /lock360.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:56:29 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:56:34 +0330] "GET /cjfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:56:38 +0330] "GET /repeater.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:56:43 +0330] "GET /cloud.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:56:49 +0330] "GET /radio.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:02 +0330] "GET /wp-content/plugins/press/wp-class.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:07 +0330] "GET /fm1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:13 +0330] "GET /M1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:14 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:29 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:34 +0330] "GET /wp-admin/css/colors/blue/CasperExV1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:39 +0330] "GET /wp-content/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:44 +0330] "GET /byp.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:57:53 +0330] "GET /edit-comments.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:58:02 +0330] "GET /smm.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:58:03 +0330] "GET /cloud.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:58:08 +0330] "GET /wp.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:58:22 +0330] "GET /1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:58:26 +0330] "GET /classwithtostring.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:58:31 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:50:58 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:51:07 +0330] "GET /wp-includes/sid.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:51:07 +0330] "GET /xleet-shell.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:51:08 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:51:11 +0330] "GET /radio.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:58:44 +0330] "GET /gecko.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:59:01 +0330] "GET /mini.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:59:02 +0330] "GET /user.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:59:06 +0330] "GET /0z.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:59:39 +0330] "GET /log.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:59:47 +0330] "GET /upload.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:00:00 +0330] "GET /lufix.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:01:35 +0330] "GET /wp-blog.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:01:40 +0330] "GET /wp-content/plugins/apikey/mar.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:01:46 +0330] "GET /wp-admin/images/module.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:01:51 +0330] "GET /wp-includes/radio.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:00 +0330] "GET /admin/controller/extension/wpm.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:03 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:07 +0330] "GET /payout.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:11 +0330] "GET /lock360.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:14 +0330] "GET /pi.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:18 +0330] "GET /wp-2019.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:59:23 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [05/Nov/2025:23:59:26 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:00:14 +0330] "GET /plugins.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:00:20 +0330] "GET /small.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:00:24 +0330] "GET /init.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:00:30 +0330] "GET /users.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 62.60.130.228 - - [06/Nov/2025:00:00:31 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "https://duckduckgo.com/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:00:35 +0330] "GET /doc.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:00:51 +0330] "GET /shell.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:00:56 +0330] "GET /fm.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:01:05 +0330] "GET /wp-admin/users.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:01:14 +0330] "GET /repeater.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:01:18 +0330] "GET /wso.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:01:21 +0330] "GET /shell20211028.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:49 +0330] "GET /x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:55 +0330] "GET /wp_info.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:59 +0330] "GET /fw.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:09 +0330] "GET /wp-content/upload.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:09 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:49 +0330] "GET /by.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:54 +0330] "GET /css.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:54 +0330] "GET /wp-content/plugins/instabuilder2/cache/plugins/moon.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:55 +0330] "GET /uploads/wp-blog.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:55 +0330] "GET /wp-content/plugins/Cache/dropdown.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:55 +0330] "GET /wp-includes/sodium_compat/src/Core/Curve25519/Ge/wp_blog.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:00 +0330] "GET /wp-content/shell20211028.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:05 +0330] "GET /wp-admin/includes/users.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:10 +0330] "GET /wso112233.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:19 +0330] "GET /ee.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:23 +0330] "GET /wp-content/plugins/Cache/Cache.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:31 +0330] "GET /wp-admin/shell20211028.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:02:32 +0330] "GET /01.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:20 +0330] "GET /wp-content/plugins/masterx/wpx.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:22 +0330] "GET /xml.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:29 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:03:37 +0330] "GET /403.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:04 +0330] "GET /customize.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:07 +0330] "GET /wp-admin/alfa.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:10 +0330] "GET /wp-content/up.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:15 +0330] "GET /text.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:20 +0330] "GET /style.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:29 +0330] "GET /ws.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:39 +0330] "GET /wp-includes/blocks/table/int/tmpl/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:40 +0330] "GET /wp-admin/dropdown.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:44 +0330] "GET /cp.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:53 +0330] "GET /marijuana.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:05:58 +0330] "GET /clen.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:06:07 +0330] "GET /mad.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:06:16 +0330] "GET /wp-includes/wp-class.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:06:22 +0330] "GET /wp-content/plugins/ccx/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:07:50 +0330] "GET /xx.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:02 +0330] "GET /sites/default/files/HolaDR7_70778.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:03 +0330] "GET /uploads/xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:08 +0330] "GET /google.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:28 +0330] "GET /wp-admin/setup-config.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:38 +0330] "GET /wp-2020.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:43 +0330] "GET /c.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:53 +0330] "GET /wikindex.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:54 +0330] "GET /wp-admin/xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:08:59 +0330] "GET /media-admin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:05 +0330] "GET /wp-l0gin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:11 +0330] "GET /ovatools.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:19 +0330] "GET /sidwso.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:41 +0330] "GET /wp-content/plugins/dzs-zoomsounds/1877.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:42 +0330] "GET /wp-info.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:04:50 +0330] "GET /sett.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:06:36 +0330] "GET /wp-content/themes/twentytwenty/404.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:06:39 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:06:59 +0330] "GET /admin/controller/extension/extension/Not_Found.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:07:05 +0330] "GET /makhdmax.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:07:10 +0330] "GET /wp-includes/js/tinymce/skins/lightgray/fonts/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:07:15 +0330] "GET /default.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:07:19 +0330] "GET /wp-admin/wso112233.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:07:32 +0330] "GET /fox.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:07:38 +0330] "GET /wp-content/plugins/linkpreview/wp-blog.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:58 +0330] "GET /nice.php?p= HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:03 +0330] "GET /wp-content/plugins/core-plugin/include.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:08 +0330] "GET /wp-includes/js/tinymce/plugins/compat3x/css/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:13 +0330] "GET /wp-includes/themes.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:18 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:30 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:35 +0330] "GET /wp-includes/Requests/Text/admin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:35 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:48 +0330] "GET /wp-includes/Requests/Text/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:54 +0330] "GET /wp-content/plugins/core/include.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:59 +0330] "GET /wp-head.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:04 +0330] "GET /wp-content/themes/twenty/twenty.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:12 +0330] "GET /wp-admin/maint/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:17 +0330] "GET /wp-content/plugins/press/wp-class.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:23 +0330] "GET /fm1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:27 +0330] "GET /wp-includes/random_compat/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:29 +0330] "GET /M1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:29 +0330] "GET /.well-known/acme-challenge/license.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:31 +0330] "GET /xl2023x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:27 +0330] "GET /worksec.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:31 +0330] "GET /todo.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:36 +0330] "GET /upl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:44 +0330] "GET /aver.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:09:46 +0330] "GET /wp-content/plugins/content-management/content.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:13 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:22 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:43 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:51 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:10:59 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:06 +0330] "GET /.well-known/acme-challenge/lpr2sn/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:13 +0330] "GET /.well-known/acme-challenge/rdlkzb/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:18 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:31 +0330] "GET /wp-admin/js/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:37 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:51 +0330] "GET /images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:48 +0330] "GET /.well-known/pki-validation/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:52 +0330] "GET /xleet-shell.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:36 +0330] "GET /xxl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:41 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:46 +0330] "GET /xl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:46 +0330] "GET /wp-content/languages/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:51 +0330] "GET /wp-admin/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:57 +0330] "GET /wp-includes/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:11:57 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:01 +0330] "GET /.well-known/acme-challenge/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:06 +0330] "GET /wp-admin/includes/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:13 +0330] "GET /wp-admin/maint/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:17 +0330] "GET /wp-content/upgrade/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:20 +0330] "GET /images/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:24 +0330] "GET /wp-admin/user/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:29 +0330] "GET /wp-admin/js/widgets/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:31 +0330] "GET /wp-admin/network/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:36 +0330] "GET /wp-admin/images/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:13:33 +0330] "GET /wp-admin/includes/themes.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:13:58 +0330] "GET /woh.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:02 +0330] "GET /sgd.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:12 +0330] "GET /file.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:14 +0330] "GET /Simple.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:26 +0330] "GET /wp-blog-header.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:34 +0330] "GET /style2.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:39 +0330] "GET /wp-conflg.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:44 +0330] "GET /class.api.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:49 +0330] "GET /install.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:52 +0330] "GET /wp-add.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:14:57 +0330] "GET /LA.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:04 +0330] "GET /wp-good.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:08 +0330] "GET /wp-ldd.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:12 +0330] "GET /upfile.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:22 +0330] "GET /xmrlpc.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:24 +0330] "GET /cong.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:29 +0330] "GET /zany.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:12:58 +0330] "GET /admin-heade.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:13:05 +0330] "GET /cgi-bin/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:13:14 +0330] "GET /wp-content/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:13:19 +0330] "GET /wp-content/uploads/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:13:46 +0330] "GET /wp-content/11.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:30 +0330] "GET /87.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:31 +0330] "GET /wboom.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:35 +0330] "GET /tuny.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:47 +0330] "GET /gettest.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:52 +0330] "GET /wp-ok.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:54 +0330] "GET /geju.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:17:03 +0330] "GET /plugin-install.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:17:07 +0330] "GET /fun.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:17:16 +0330] "GET /trust.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:17:18 +0330] "GET /godsend.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:17:29 +0330] "GET /wp-theme.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:17:50 +0330] "GET /wp-scripts.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:17:57 +0330] "GET /wp-editor.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:57 +0330] "GET /chtmlfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:02 +0330] "GET /cjfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:07 +0330] "GET /classsmtps.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:15 +0330] "GET /classfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:25 +0330] "GET /comfunctions.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:31 +0330] "GET /comdofuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:45 +0330] "GET /connects.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:48 +0330] "GET /copypaths.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:53 +0330] "GET /delpaths.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:19:58 +0330] "GET /doiconvs.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:20:03 +0330] "GET /epinyins.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:20:07 +0330] "GET /filefuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:20:17 +0330] "GET /gdftps.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:20:20 +0330] "GET /hinfofuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:20:30 +0330] "GET /hplfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:20:33 +0330] "GET /memberfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:20:42 +0330] "GET /moddofuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:20:55 +0330] "GET /onclickfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:21:08 +0330] "GET /phpzipincs.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:33 +0330] "GET /ayk.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:42 +0330] "GET /cd.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:47 +0330] "GET /reune.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:15:51 +0330] "GET /wp-admin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:00 +0330] "GET /TNT.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:09 +0330] "GET /bak.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:16:12 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:10 +0330] "GET /mah.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:15 +0330] "GET /jp.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:29 +0330] "GET /ext.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:30 +0330] "GET /a.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:33 +0330] "GET /wp-zett.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:34 +0330] "GET /LV.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:37 +0330] "GET /inputs.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:18:44 +0330] "GET /adminfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:21:42 +0330] "GET /siteheads.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:21:56 +0330] "GET /termps.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:22:00 +0330] "GET /txets.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:22:57 +0330] "GET /wp-settings.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:23:02 +0330] "GET /wp-trackback.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:23:06 +0330] "GET /wp-activate.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:23:16 +0330] "GET /wp-comments-post.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:23:41 +0330] "GET /wp-load.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:23:51 +0330] "GET /wp-mail.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:00 +0330] "GET /wp-signup.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:03 +0330] "GET /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:07 +0330] "GET /edit-form-advanced.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:09 +0330] "GET /link-parse-opml.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:09 +0330] "GET /ms-sites.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:10 +0330] "GET /options-writing.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:15 +0330] "GET /admin-ajax.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:24 +0330] "GET /edit-form-comment.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:48 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:21:14 +0330] "GET /qfunctions.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:21:18 +0330] "GET /qinfofuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:21:21 +0330] "GET /schallfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:21:27 +0330] "GET /tempfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:21:29 +0330] "GET /userfuns.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:22:13 +0330] "GET /thoms.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:22:18 +0330] "GET /postnews.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:22:28 +0330] "GET /wp-config-sample.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:22:42 +0330] "GET /wp-links-opml.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:23:30 +0330] "GET /wp-cron.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:36 +0330] "GET /link.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:25:29 +0330] "GET /wordpress/wp-admin/includes HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:25:38 +0330] "GET /wp-admin/js/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:25:43 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:25:53 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:25:59 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:08 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:18 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:19 +0330] "GET /wp-includes/ID3 HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:24 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:30 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:42 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:43 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:52 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:26:53 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:27:12 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:27:12 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:27:21 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:27:36 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:27:41 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:13 +0330] "GET /wp-content/uploads/ao_ccss/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:14 +0330] "GET /wp-content/uploads/2021/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:52 +0330] "GET /.well-known/pki-validation/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:24:58 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:25:04 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:25:13 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:25:16 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:01 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:13 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:19 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:25 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:31 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:35 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:36 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:45 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:28:55 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:01 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:17 +0330] "GET /wp-content/plugins/elementor/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:17 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:17 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:20 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:30 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:34 +0330] "GET /uploads/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:38 +0330] "GET /wordpress/wp-content/uploads/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:39 +0330] "GET /wordpress/wp-includes/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:55 +0330] "GET /blog/wp-includes/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:29:58 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:30:07 +0330] "GET /WordPress/wp-admin/includes/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:30:09 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:30:14 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:30:17 +0330] "GET /wp-content/themes/twentytwentythree/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 172.93.148.172 - - [06/Nov/2025:00:30:20 +0330] "GET /wp-content/themes/twentytwentytwo/ HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 194.165.16.8 - - [06/Nov/2025:01:07:23 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0" 194.165.16.8 - - [06/Nov/2025:02:21:30 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0" 41.141.91.154 - - [06/Nov/2025:04:21:59 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:04:50:50 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:04:50:58 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:04:51:26 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.249.34.184 - - [06/Nov/2025:04:51:58 +0330] "GET /ss.php?f_c=1 HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:04:50:07 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:04:50:07 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 173.249.34.184 - - [06/Nov/2025:04:51:50 +0330] "GET /postnews.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:04:51:57 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:04:52:15 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:04:55:45 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:03:33 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:31:23 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:34:59 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:37:06 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:37:26 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:38:43 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:39:13 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:40:49 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:41:57 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:41:59 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:42:01 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:42:05 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:42:21 +0330] "GET /smtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 41.141.91.154 - - [06/Nov/2025:05:42:27 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:42:35 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:42:40 +0330] "GET /wp-admin/network/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:42:49 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:44:28 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:36:35 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:37:01 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:37:05 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:37:26 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:39:09 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:39:21 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:39:21 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:40:24 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:40:59 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:42:31 +0330] "GET /wp-includes/Text/mar.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 41.141.91.154 - - [06/Nov/2025:05:44:15 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:46:51 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:47:20 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:49:02 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:49:05 +0330] "GET /smtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 41.141.91.154 - - [06/Nov/2025:05:49:09 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:44:36 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:44:41 +0330] "GET /wp-admin/network/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:45:12 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:48:51 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:48:52 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:50:44 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:51:26 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:54:51 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:55:29 +0330] "GET /chosen.php?p= HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:56:23 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:56:52 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:57:00 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:57:15 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:01:14 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:04:57 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:05:05 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:07:34 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:52:45 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:54:12 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:58:11 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:58:25 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:05:58:27 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:00:42 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:00:47 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:01:01 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:01:14 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:03:28 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:03:45 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:04:57 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:05:25 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:05:46 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:10:43 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:11:07 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:11:21 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:00 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:00 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:05 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:08 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:21 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:36 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:18:11 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:18:36 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:18:36 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:18:57 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:19:05 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:19:34 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:19:46 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:22:22 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:22:23 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:22:25 +0330] "GET /wp-admin/network/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:10:07 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:10:32 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:10:35 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:10:55 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:11:34 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:12:46 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:12:47 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:09 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:53 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:58 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:14:59 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:17:21 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:18:12 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:19:04 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:19:13 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:19:27 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:19:39 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:20:06 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:28:52 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:29:08 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:29:12 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:30:00 +0330] "GET /smtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 41.141.91.154 - - [06/Nov/2025:06:30:13 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:29:14 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:30:18 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:30:55 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:32:47 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:32:50 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:33:28 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:38:24 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:41:29 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 212.132.117.179 - - [06/Nov/2025:06:42:49 +0330] "POST /wp-login.php HTTP/1.1" 301 795 "http://app.optimyar.com/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:44:58 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:45:02 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:45:14 +0330] "GET /wp-includes/Text/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:48:52 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:51:25 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:45:11 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:51:44 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:06:59:16 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 194.165.16.8 - - [06/Nov/2025:07:00:57 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0" 41.141.91.154 - - [06/Nov/2025:07:01:53 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:04:40 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:05:51 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:04:39 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:04:56 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:09:58 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:19:43 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:21:53 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 194.165.16.8 - - [06/Nov/2025:07:29:20 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15" 41.141.91.154 - - [06/Nov/2025:07:19:11 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:19:13 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:19:42 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:19:49 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:19:51 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:21:52 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:07:35:38 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:04:39 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:04:42 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:04:44 +0330] "GET /wp-admin/network/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:04:48 +0330] "GET /cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:12:33 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:13:52 +0330] "GET /504.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:19:04 +0330] "GET /chosen.php?p= HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:20:29 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:20:37 +0330] "GET /wp-content/themes/gaukingo/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:12:35 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:15:20 +0330] "GET /smtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 41.141.91.154 - - [06/Nov/2025:08:17:42 +0330] "GET /chosen.php?p= HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:20:30 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:20:34 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:20:37 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:24:50 +0330] "GET /chosen.php?p= HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:27:05 +0330] "GET /chosen.php?p= HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:27:55 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:28:10 +0330] "GET /.well-known/acme-challenge/atomlib.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:29:21 +0330] "GET /504.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:30:03 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:27:57 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:27:58 +0330] "GET /wp-admin/network/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:30:11 +0330] "GET /504.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:30:21 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:30:24 +0330] "GET /wp-content/themes/gaukingo/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:31:53 +0330] "GET /smtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 41.141.91.154 - - [06/Nov/2025:08:33:15 +0330] "GET /wp-admin/css/colors/blue/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:37:08 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:30:15 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:30:21 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:30:23 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:31:52 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:32:41 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:34:44 +0330] "GET /wp-includes/Requests/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:37:07 +0330] "GET /.well-known/pki-validation/atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 141.98.11.16 - - [06/Nov/2025:08:47:29 +0330] "GET /postnews.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:50:50 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 194.165.16.8 - - [06/Nov/2025:08:51:32 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15" 41.141.91.154 - - [06/Nov/2025:08:53:58 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:39:39 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:39:40 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:40:03 +0330] "GET /file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:46:26 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:50:53 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:51:24 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:51:24 +0330] "GET /wp-content/themes/gaukingo/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:51:25 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:51:26 +0330] "GET /wp-content/plugins/ioptimization/IOptimize.php?rchk HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:08:59:01 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:09:04:08 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:09:07:12 +0330] "GET /xxl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:09:08:14 +0330] "GET /x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:09:01:35 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:09:05:20 +0330] "GET /xl2023x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:09:05:37 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:09:09:49 +0330] "GET /xl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:09:11:57 +0330] "GET /wp-admin/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 158.94.208.149 - - [06/Nov/2025:11:22:27 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 43.159.144.16 - - [06/Nov/2025:12:19:59 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 205.169.39.7 - - [06/Nov/2025:13:39:51 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36" 180.242.130.29 - - [06/Nov/2025:14:42:40 +0330] "GET /wp-content/plugins/wps-hide-login/wps-hide-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0" 194.165.16.8 - - [06/Nov/2025:15:30:11 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:11 +0330] "GET /manager.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:11 +0330] "GET /bless.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:11 +0330] "GET /O-Simple.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:12 +0330] "GET /lock360.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:12 +0330] "GET /zwso.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:12 +0330] "GET /chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:12 +0330] "GET /about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:13 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:13 +0330] "GET /.well-known/login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:13 +0330] "GET /mah.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:13 +0330] "GET /.wp/wso.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:14 +0330] "GET /core.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:14 +0330] "GET /robots.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:14 +0330] "GET /inputs.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:14 +0330] "GET /mini.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:15 +0330] "GET /goods.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:15 +0330] "GET /file5.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:53:15 +0330] "GET /ahax.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:15 +0330] "GET /f35.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:16 +0330] "GET /simple.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:16 +0330] "GET /update/f35.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:16 +0330] "GET /wp-content/hello.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:16 +0330] "GET /wp-admin/maint/bootstrap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:17 +0330] "GET /themes/zMousse/otuz1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:17 +0330] "GET /wp-content/edit-wolf.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:17 +0330] "GET /wp-content/plugins/ubh/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:17 +0330] "GET /wp-admin/images/bootstrap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:17 +0330] "GET /images/upload.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:18 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:18 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:18 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:18 +0330] "GET /admin/uploads/bn_1_1754420677.phtml HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:53:19 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:19 +0330] "GET /wp-content/plugins/pwnd/pwnd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:19 +0330] "GET /wp-content/plugins/pwnd-1/pwnd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:53:19 +0330] "GET /wp-admin/css/colors/midnight/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:20 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/kill.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:20 +0330] "GET /wp-includes/style-engine/worksec.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:20 +0330] "GET /wp-admin/images/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:20 +0330] "GET /wp-content/plugins/core-plugin/include.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:53:21 +0330] "GET /wp-content/plugins/envato-css.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:21 +0330] "GET /classwithtostring.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:53:21 +0330] "GET /uploads/94056-upload.phtml HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:21 +0330] "GET /index/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:22 +0330] "GET /tinyfilemanager.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:22 +0330] "GET /js/bas.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:22 +0330] "GET /.well-known/pki-validation/moon.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:53:22 +0330] "GET /file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:23 +0330] "GET /wp-includes/js/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:23 +0330] "GET /wp-content/upgrade/item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:23 +0330] "GET /buy.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:23 +0330] "GET /wp-content/languages/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:24 +0330] "GET /wp-content/themes/classwithtostring.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:24 +0330] "GET /wp-content/plugins/elementor/wp-wjvngrh.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:24 +0330] "GET /wp-includes/IXR/fix.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:24 +0330] "GET /wp-includes/widgets/dyqvcfqv.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:53:25 +0330] "GET /admin/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:25 +0330] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:25 +0330] "GET /wp-includes/js/crop/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:25 +0330] "GET /wp-includes/PHPMailer/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:26 +0330] "GET /wp-includes/PHPMailer/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:26 +0330] "GET /wp-includes/widgets/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:26 +0330] "GET /files/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:26 +0330] "GET /wp-includes/PHPMailer/options.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:27 +0330] "GET /inc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:27 +0330] "GET /wp-content/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:27 +0330] "GET /filemanager.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:27 +0330] "GET /cgi-bin/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:28 +0330] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:28 +0330] "GET /wp-includes/IXR/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:28 +0330] "GET /wp-admin/js/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:28 +0330] "GET /wp-includes/js/jquery/jquery.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:29 +0330] "GET /function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:29 +0330] "GET /wp-includes/block-supports/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:29 +0330] "GET /wp-signup.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:29 +0330] "GET /wp-admin/network/network.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:30 +0330] "GET /admin/upload/css.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:30 +0330] "GET /wp-blog.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:30 +0330] "GET /wp-admin/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:53:30 +0330] "GET /wp-content/plugins/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:31 +0330] "GET /wp-includes/blocks/table/int/tmpl/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:31 +0330] "GET /wp-l0gin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:53:31 +0330] "GET /wp-includes/js/jquery/suggest.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:31 +0330] "GET /new.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:32 +0330] "GET /wp-content/plugins/pwnd-1/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:53:32 +0330] "GET /wp-includes/defaults.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:32 +0330] "GET /images/DJP9.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:32 +0330] "GET /wp-includes/customize/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:33 +0330] "GET /wp-admin/shell20211028.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:33 +0330] "GET /natural.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:33 +0330] "GET /item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:33 +0330] "GET /function/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:34 +0330] "GET /wp-includes/SimplePie/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:34 +0330] "GET /wp-admin/images/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:34 +0330] "GET /wp-includes/theme-compat/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:34 +0330] "GET /about/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:53:35 +0330] "GET /wp-includes/Requests/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:35 +0330] "GET /wp-includes/ID3/about.php/wp-content/x/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:53:35 +0330] "GET /wp-includes/ID3/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:35 +0330] "GET /wp-content/languages/404.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:36 +0330] "GET /update/403.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:36 +0330] "GET /default.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:36 +0330] "GET /wp-includes/assets/info.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:36 +0330] "GET /wp-includes/class.api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:37 +0330] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:37 +0330] "GET /wp-admin/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:37 +0330] "GET /autoload_classmap/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:37 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:38 +0330] "GET /images/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:38 +0330] "GET /db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:38 +0330] "GET /.well-known/pki-validation/mariju.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:38 +0330] "GET /mah/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:53:39 +0330] "GET /wp-content/plugins/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:39 +0330] "GET /wp-includes/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:53:39 +0330] "GET /wp-content/themes/tflow/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:53:39 +0330] "GET /wp-admin/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:53:40 +0330] "GET /templates/beez3/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:40 +0330] "GET /wp-admin/js/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:40 +0330] "GET /install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:40 +0330] "GET /wp-admin/css/colors/blue/rk2.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:41 +0330] "GET /images/class-config.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:41 +0330] "GET /components/com_jea/views/form/tmpl/size.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:41 +0330] "GET /templates/beez/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:41 +0330] "GET /bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:53:42 +0330] "GET /class.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:42 +0330] "GET /wp-admin/css/colors/light/profile.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:42 +0330] "GET /wp-content/product.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:42 +0330] "GET /wp-content/uploads/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:43 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ask.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:43 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:43 +0330] "GET /css/css.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:43 +0330] "GET /init.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:44 +0330] "GET /wp-admin/user/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:44 +0330] "GET /autoload_classmap/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:44 +0330] "GET /wp-includes/item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:44 +0330] "GET /assets/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:53:45 +0330] "GET /.well-known/pki-validation/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:45 +0330] "GET /wp-content/uploads/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:45 +0330] "GET /css/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:45 +0330] "GET /adminfuns.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:46 +0330] "GET /wp-admin/css/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:46 +0330] "GET /wp_wlx.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:46 +0330] "GET /wp-admin/js/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:46 +0330] "GET /wp-includes/assets/husky301.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:47 +0330] "GET /wp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:47 +0330] "GET /wp-admin/css/colors/blue/wp-trackback.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:47 +0330] "GET /wp-content/themes/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:47 +0330] "GET /wp-header.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:48 +0330] "GET /wp-content/themes/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:48 +0330] "GET /Marvins.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:48 +0330] "GET /wp-content/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:48 +0330] "GET /wp-class.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:48 +0330] "GET /wp-includes/images/smilies/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:53:49 +0330] "GET /xx.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:53:49 +0330] "GET /autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:53:49 +0330] "GET /wp-includes/classwithtostring.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:49 +0330] "GET /wp-content/blue.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:50 +0330] "GET /content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:53:50 +0330] "GET /wp-content/uploads/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:50 +0330] "GET /wp-admin/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:50 +0330] "GET /wp-includes/rest-api/endpoints/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:51 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:51 +0330] "GET /wp-content/plugins/wp-theme-editor/include.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:53:51 +0330] "GET /wp-content/plugins/up/main.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:51 +0330] "GET /fonts/fontawesome-webfont.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:52 +0330] "GET /wp-admin/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:53:52 +0330] "GET /wp-admin/includes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:52 +0330] "GET /wp-admin/css/colors/blue/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:53 +0330] "GET /images/images/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:53 +0330] "GET /images/class.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:53 +0330] "GET /wp-content/plugins/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:53:53 +0330] "GET /web.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:54 +0330] "GET /wp-admin/css/colors/ocean/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:53:54 +0330] "GET /images/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:54 +0330] "GET /wp-content/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:54 +0330] "GET /.well-known/gecko-litespeed.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:55 +0330] "GET /wp-admin/css/colors/midnight/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:55 +0330] "GET /wp-trackback.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:55 +0330] "GET /wp-includes/style-engine/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:55 +0330] "GET /radio.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:56 +0330] "GET /wp-admin/mah.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:56 +0330] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:56 +0330] "GET /wp-admin/css/colors/midnight/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:53:56 +0330] "GET /wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:57 +0330] "GET /wp-setup.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:57 +0330] "GET /ms-themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:53:57 +0330] "GET /wp-includes/assets/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:57 +0330] "GET /style.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:53:58 +0330] "GET /wp-includes/infi.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:58 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:53:58 +0330] "GET /x.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:58 +0330] "GET /wp-includes/IXR/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:53:59 +0330] "GET /css/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:53:59 +0330] "GET /images/index22.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:53:59 +0330] "GET /wp-user.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:53:59 +0330] "GET /wp-includes/pomo/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:00 +0330] "GET /wp-includes/pomo/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:00 +0330] "GET /config.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:54:00 +0330] "GET /special.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:54:00 +0330] "GET /assets/script.js.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:01 +0330] "GET /wp-content/themes/twentytwentythree/patterns/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:01 +0330] "GET /wp-admin/css/colors/sunrise/colors_95.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:01 +0330] "GET /wp-includes/block-patterns/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:01 +0330] "GET /wp-content/uploads/wp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:02 +0330] "GET /wp-includes/certificates/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:02 +0330] "GET /cgi-bin/class.api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:02 +0330] "GET /wp-content/cache/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:02 +0330] "GET /wp-admin/css/colors/blue/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:03 +0330] "GET /wp-includes/edit.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:03 +0330] "GET /webdb.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:54:03 +0330] "GET /assets/images/doc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:03 +0330] "GET /file2.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:04 +0330] "GET /wp-includes/ID3/wp-work.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:04 +0330] "GET /alfa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:04 +0330] "GET /wp-admin/css/colors/blue/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:04 +0330] "GET /wp-includes/click.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:04 +0330] "GET /.well-known/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:54:05 +0330] "GET /wp-admin/css/colors/blue/atomlib.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:05 +0330] "GET /wp-admin/js/widgets/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:05 +0330] "GET /wp-includes/random_compat/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:05 +0330] "GET /wp-admin/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:06 +0330] "GET /edit.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:06 +0330] "GET /wp-content/plugins/WordPressCore/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:06 +0330] "GET /cgi-bin/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:54:06 +0330] "GET /wp-links-opml.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:54:07 +0330] "GET /wp-admin/user/network.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:07 +0330] "GET /atomlib.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:07 +0330] "GET /wp-includes/js/jquery/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:07 +0330] "GET /wp-includes/xl2023.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:08 +0330] "GET /wp-includes/certificates/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:08 +0330] "GET /wp-includes/images/media/dog.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:08 +0330] "GET /xp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:08 +0330] "GET /wp-includes/SimplePie/applicationd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:09 +0330] "GET /wp-includes/assets/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:54:09 +0330] "GET /wp-links.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:09 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:09 +0330] "GET /wp-includes/css/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:54:10 +0330] "GET /wp-includes/ID3/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:10 +0330] "GET /wp-includes/pomo/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:10 +0330] "GET /wp-includes/IXR/security.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:10 +0330] "GET /wp-content/plugins/phpadmin/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:11 +0330] "GET /wp-includes/Requests/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:54:11 +0330] "GET /wp-content/plugins/hello.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:11 +0330] "GET /wp-content/plugins/seoo/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:11 +0330] "GET /wp-includes/fonts/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:12 +0330] "GET /moon.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:54:12 +0330] "GET /wp-admin/user/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:12 +0330] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:12 +0330] "GET /webadmin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:13 +0330] "GET /wp-includes/PHPMailer/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:13 +0330] "GET /wp-admin/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:13 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:54:13 +0330] "GET /go.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:14 +0330] "GET /wp-admin/xleet.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:14 +0330] "GET /templates/beez3/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:14 +0330] "GET /wp-admin/css/colors/blue/ahax.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:54:14 +0330] "GET /.well-known/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:15 +0330] "GET /wp-includes/assets/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:15 +0330] "GET /cgi-bin/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:15 +0330] "GET /wp-content/uploads/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:15 +0330] "GET /wp-content/plugins/view-more/ioxi.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:16 +0330] "GET /wp-includes/customize/dedi1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:16 +0330] "GET /wp-includes/pomo/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:16 +0330] "GET /wp-admin/css/colors/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:16 +0330] "GET /warm.PhP7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:17 +0330] "GET /wp-admin/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:17 +0330] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:54:17 +0330] "GET /wp-includes/images/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:54:17 +0330] "GET /wp-content/plugins/ioxi/ioxiworm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:54:18 +0330] "GET /blog/wp-content/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:18 +0330] "GET /hehehehe.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:18 +0330] "GET /.well-known/acme-challenge/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:18 +0330] "GET /.well-known/acme-challenge/plugins.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:54:19 +0330] "GET /.well-known/acme-challenge/license.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:19 +0330] "GET /wp-content/themes/astra/inc/ki1k.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:54:19 +0330] "GET /wp-content/themes/astra/inc/fm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:54:19 +0330] "GET /wp-content/plugins/ccx/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:54:20 +0330] "GET /wp-content/themes/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:20 +0330] "GET /wp-includes/Requests/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:54:20 +0330] "GET /wp-includes/css/dist/edit-widgets/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:20 +0330] "GET /wp-includes/css/dist/edit-widgets/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:21 +0330] "GET /wp-includes/Requests/src/Exception/Http/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:54:21 +0330] "GET /wp-includes/Text/Diff/Renderer/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:21 +0330] "GET /wp-includes/Text/Diff/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:21 +0330] "GET /wp-admin/css/colors/ocean/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:22 +0330] "GET /wp-includes/images/media/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:22 +0330] "GET /wp-includes/js/tinymce/skins/lightgray/img/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:22 +0330] "GET /wp-includes/js/tinymce/skins/lightgray/img/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:22 +0330] "GET /wp-includes/js/tinymce/skins/lightgray/img/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:23 +0330] "GET /wp-admin/maint/themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:54:23 +0330] "GET /wp-content/plugins/seoplugins/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:54:23 +0330] "GET /wp-includes/fonts/themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:23 +0330] "GET /wp-content/themes/twentytwentytwo/assets/fonts/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:24 +0330] "GET /wp-includes/certificates/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:24 +0330] "GET /byp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:24 +0330] "GET /blog/wp-includes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:24 +0330] "GET /wp-includes/images/media/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:25 +0330] "GET /blog/wp-admin/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:25 +0330] "GET /wp-content/themes/twentyfive/include.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:25 +0330] "GET /wp-includes/css/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:25 +0330] "GET /cgi-bin/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:26 +0330] "GET /wp-content/wso.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:26 +0330] "GET /class.api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:26 +0330] "GET /wp-includes/certificates/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:54:26 +0330] "GET /wp-content/radio.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:27 +0330] "GET /system_log.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:54:27 +0330] "GET /.alf.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:27 +0330] "GET /wso.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:27 +0330] "GET /wp-includes/blocks/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:28 +0330] "GET /flower.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:28 +0330] "GET /wp-includes/wp-class.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:28 +0330] "GET /wp-admin/js/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:28 +0330] "GET /wp-content/1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:29 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:29 +0330] "GET /info.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:29 +0330] "GET /setup.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:54:29 +0330] "GET /.bod/.ll/ss.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:30 +0330] "GET /.well-known/radio.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:30 +0330] "GET /wp-content/plugin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:54:30 +0330] "GET /wp-admin/css/colors/ectoplasm/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:54:30 +0330] "GET /as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:31 +0330] "GET /cc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:54:31 +0330] "GET /.well-known/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:31 +0330] "GET /ab.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:31 +0330] "GET /wp-content/themes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:32 +0330] "GET /wp-content/themes/twentytwentytwo/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:32 +0330] "GET /doc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:32 +0330] "GET /wp-includes/html-api/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:32 +0330] "GET /wp-includes/style-engine/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:33 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:33 +0330] "GET /mar.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:33 +0330] "GET /wp-includes/sitemaps/providers/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:33 +0330] "GET /wp-admin/css/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:34 +0330] "GET /1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:34 +0330] "GET /wp-includes/Text/Diff/Engine/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:34 +0330] "GET /wp-includes/style-engine/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:54:34 +0330] "GET /js/fm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:35 +0330] "GET /wp-admin/images/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:54:35 +0330] "GET /wp-content/uploads/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:35 +0330] "GET /wp-content/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:54:35 +0330] "GET /wp-includes/Text/Diff/Engine/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:54:36 +0330] "GET /fm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:54:36 +0330] "GET /wp-admin/js/widgets/cloud.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:36 +0330] "GET /adminfuns.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:36 +0330] "GET /wp-admin/images/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:37 +0330] "GET /ini.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:54:37 +0330] "GET /wp-admin/css/colors/coffee/cloud.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:54:37 +0330] "GET /wp-includes/blocks/calendar/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:37 +0330] "GET /admin/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:54:38 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:38 +0330] "GET /.well-known/acme-challenge/atomlib.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:38 +0330] "GET /wp-admin/js/instaall.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:38 +0330] "GET /wp-includes/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:39 +0330] "GET /wp-includes/plugins.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:39 +0330] "GET /wp-content/plugins/atomlib.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:39 +0330] "GET /wp-content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:39 +0330] "GET /wp-includes/css/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:40 +0330] "GET /wp-includes/Text/Diff/Renderer/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:40 +0330] "GET /wp-admin/network/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:40 +0330] "GET /wp-admin/css/colors/light/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:40 +0330] "GET /customize.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:41 +0330] "GET /license.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:54:41 +0330] "GET /wp-content/languages/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:54:41 +0330] "GET /lock.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:41 +0330] "GET /wp-admin/css/colors/blue/gold.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:54:42 +0330] "GET /wp-includes/atomlib.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:42 +0330] "GET /wp-includes/rest-api/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:42 +0330] "GET /.well-known/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:42 +0330] "GET /.well-known/wincust.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:43 +0330] "GET /wp-admin/css/colors/light/alfa-rex.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:43 +0330] "GET /wp-good.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:43 +0330] "GET /wp-includes/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:43 +0330] "GET /wp-includes/style-engine/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:54:44 +0330] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:44 +0330] "GET /wp-content/themes/twentytwentyfour/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:44 +0330] "GET /randkeyword.PhP7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:44 +0330] "GET /wp-admin/js/widgets/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:45 +0330] "GET /fonts/database.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:45 +0330] "GET /ff2.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:54:45 +0330] "GET /wp-includes/SimplePie/Exception-wp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:45 +0330] "GET /wp-admin/plugin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:46 +0330] "GET /wp-includes/rest-api/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:46 +0330] "GET /jp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:46 +0330] "GET /wp-atom.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:46 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:47 +0330] "GET /up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:54:47 +0330] "GET /wp-content/uploads/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:54:47 +0330] "GET /assets/images/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:54:47 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:54:48 +0330] "GET /js/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:48 +0330] "GET /simple/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:48 +0330] "GET /worm.PhP HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:48 +0330] "GET /ext.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:49 +0330] "GET /delpaths.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:54:49 +0330] "GET /.well-known/pki-validation/1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:49 +0330] "GET /wp-includes/bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:54:49 +0330] "GET /wp-content/plugins/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:54:50 +0330] "GET /.well-known/pki-validation/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:50 +0330] "GET /wp-admin/css/colors/sunrise/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:54:50 +0330] "GET /gifclass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:50 +0330] "GET /plugin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:51 +0330] "GET /wp-content/themes/twentytwentyfour/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:51 +0330] "GET /update-core.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:51 +0330] "GET /wp-admin/css/colors/blue/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:51 +0330] "GET /wp-mail.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:52 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:52 +0330] "GET /wp-admin/defaults.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:52 +0330] "GET /.well-known/acme-challenge/content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:52 +0330] "GET /wp-content/ALFA_DATA/alfacgiapi/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:53 +0330] "GET /wp-admin/maint/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:53 +0330] "GET /wp-admin/js/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:53 +0330] "GET /wp-content/uploads/2023/05/404.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:53 +0330] "GET /wp-admin/maint/maint.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:54 +0330] "GET /assets/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:54 +0330] "GET /aa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:54 +0330] "GET /index2.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:54:54 +0330] "GET /wp-content/themes/hello-element/footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:55 +0330] "GET /wp-admin/network/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:54:55 +0330] "GET /.well-known/pki-validation/2index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:54:55 +0330] "GET /wp-content/languages/plugins.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:54:55 +0330] "GET /shell.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:56 +0330] "GET /.well-known/content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:56 +0330] "GET /wp-includes/Text/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:00 +0330] "GET /wp-admin/wso.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:00 +0330] "GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:01 +0330] "GET /contacts.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:01 +0330] "GET /wsa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:01 +0330] "GET /wp-includes/SimplePie/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:01 +0330] "GET /firewall.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:55:02 +0330] "GET /wp-includes/sodium_compat/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:02 +0330] "GET /wp-content/uploads/content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:02 +0330] "GET /lv.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:02 +0330] "GET /images/js1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:03 +0330] "GET /wp-admin/maint/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:03 +0330] "GET /.well-known/acme-challenge/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:03 +0330] "GET /.well-known/acme-challenge/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:03 +0330] "GET /wp-includes/images/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:55:04 +0330] "GET /wp-includes/ID3/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:04 +0330] "GET /wp-admin/theme-editor.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:04 +0330] "GET /wp-admin/css/colors/blue/abc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:55:04 +0330] "GET /wp-admin/maint/wonder.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:05 +0330] "GET /wp-content/themes/twentytwentyfour/wonder.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:05 +0330] "GET /wp-content/plugins/fix/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:05 +0330] "GET /tox.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:05 +0330] "GET /wp-content/languages/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:06 +0330] "GET /wp-includes/js/dist/default.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:06 +0330] "GET /wp-admin/css/colors/tfileman.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:06 +0330] "GET /tiny.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:06 +0330] "GET /wp-admin/js/widgets/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:07 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:07 +0330] "GET /wp-themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:07 +0330] "GET /wp-includes/sodium_compat/src/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:07 +0330] "GET /wp-content/plugins/erinyani/asasx.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:08 +0330] "GET /mariju.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:08 +0330] "GET /waf_defender.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:08 +0330] "GET /wp-admin/maint/cong.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:08 +0330] "GET /av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:09 +0330] "GET /wp-admin/css/glex.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:09 +0330] "GET /wp-admin/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:55:09 +0330] "GET /wp-includes/SimplePie/Parse/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:09 +0330] "GET /.well-known/acme-challenge/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:10 +0330] "GET /wp-content/themes/twentytwentyfour/system_cache.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:10 +0330] "GET /wp-content/themes/sky-pro/js.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:10 +0330] "GET /wp-includes/Text/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:55:10 +0330] "GET /wp-content/themes/pridmag/waf_defender.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:11 +0330] "GET /theme.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:11 +0330] "GET /wp-content/themes/twentytwentytwo/waf_defender.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:11 +0330] "GET /wp-admin/css/colors/coffee/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:11 +0330] "GET /Simple.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:12 +0330] "GET /.well-known/acme-challenge/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:12 +0330] "GET /wp-admin/1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:12 +0330] "GET /wp-admin/css/colors/ocean/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:12 +0330] "GET /wp-content/plugins/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:55:13 +0330] "GET /.well-known/classwithtostring.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:13 +0330] "GET /css/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:13 +0330] "GET /images/waf_defender.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:13 +0330] "GET /wp-includes/SimplePie/Cache/upfile.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:13 +0330] "GET /small.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:14 +0330] "GET /wp-includes/js/tinymce/plugins/fullscreen/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:14 +0330] "GET /NewFile.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:14 +0330] "GET /wp-content/uploads/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:14 +0330] "GET /error.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:55:15 +0330] "GET /wp-content/plugins/pwnd/admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:15 +0330] "GET /wp-includes/widgets/class-wp-widget-search-function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:55:15 +0330] "GET /wp-content/languages/themes/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:15 +0330] "GET /wp-files.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:16 +0330] "GET /functions.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:16 +0330] "GET /admin/controller/extension/extension/cloud.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:16 +0330] "GET /wp-includes/SimplePie/Canonical.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:16 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/uss.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:17 +0330] "GET /wp-includes/certificates/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:17 +0330] "GET /aks.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:17 +0330] "GET /litespeed.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:17 +0330] "GET /img/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:18 +0330] "GET /wp-includes/class-feed-index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:18 +0330] "GET /wpn.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:18 +0330] "GET /wp-content/classwithtostring.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:18 +0330] "GET /.well-known/acme-challenge/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:19 +0330] "GET /wp-includes/customize/class-wp-customize-nav-menu-section-boolean.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:19 +0330] "GET /wp-content/themes/twentytwentyfour/functions.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:19 +0330] "GET /wp-includes/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:19 +0330] "GET /wp-includes/class-wp-dependency-float.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:20 +0330] "GET /wp-includes/PHPMailer/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:20 +0330] "GET /wp-includes/PHPMailer/purna.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:20 +0330] "GET /wp-includes/interactivity-api/interactivity-api-class.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:20 +0330] "GET /wp-includes/l10n/class-wp-widddget-pages.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:21 +0330] "GET /tinyfilemanager/tinyfilemanager.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:21 +0330] "GET /wp-admin/css/colors/light/colors.min.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:55:21 +0330] "GET /wp-includes/customize/class-wp-customize-nav-menu-auto-add-control-repository.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:21 +0330] "GET /wp-includes/assets/script-loader-react-refresh-runtime.min-soap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:22 +0330] "GET /wp-includes/ID3/module.audio-video.riff-set.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:55:22 +0330] "GET /fog/management/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:55:22 +0330] "GET /wp-includes/js/tinymce/utils/license.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:22 +0330] "GET /components/com_newsfeeds/models/indexx.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:23 +0330] "GET /images/wp-aespa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:23 +0330] "GET /wp-includes/Text/options.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:23 +0330] "GET /.well-known/acme-challenge/wp-load.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:55:23 +0330] "GET /wp-content/upgrade/cc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:24 +0330] "GET /wp-content/themes/aahana/worksec.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:24 +0330] "GET /anonse/lock360.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:24 +0330] "GET /wp-content/themes/bltm/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:24 +0330] "GET /wp-admin/includes/class_api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:55:25 +0330] "GET /plugins/content/apismtp/apismtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:25 +0330] "GET /wp-admin/includes/class-core-upgrader-first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:25 +0330] "GET /wp-admin/css/wp-css.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:25 +0330] "GET /.well-known/save.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:26 +0330] "GET /wp-includes/feed-rsss.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:26 +0330] "GET /wp-includes/IXR/goto.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:26 +0330] "GET /wp-admin/css/colors/blue/xboom.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:26 +0330] "GET /uploads/af32.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:55:27 +0330] "GET /wp-content/themes/kadence/functions.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:27 +0330] "GET /Sanskrit.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:27 +0330] "GET /wp-fmfile.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:27 +0330] "GET /.trash7309/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:28 +0330] "GET /wp-content/plugins/revslider/includes/external/page/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:32 +0330] "GET /wp-content/plugins/ubh/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:33 +0330] "GET /wp-includes/SimplePie/Registry-private.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:33 +0330] "GET /wp-includes/assets/script-modules-packages.min-meta.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:33 +0330] "GET /wp-includes/widgets/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:33 +0330] "GET /wp-content/themes/twentytwentyfour/content-index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:34 +0330] "GET /admin/controller/extension/extension/alfa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:34 +0330] "GET /wp-content/themes/twentytwentyfour/system_cache.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:34 +0330] "GET /wp-admin/css/colors/modern/colors.css.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:34 +0330] "GET /wp-includes/style-engine/adminfus.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:35 +0330] "GET /css/media-widget-vide02.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:35 +0330] "GET /wp-includes/blocks/group/wp-style.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:35 +0330] "GET /images/buy.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:55:35 +0330] "GET /templates/beez3/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:36 +0330] "GET /wp-includes/widgets/class-wp-wolf-widget.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:36 +0330] "GET /wp-admin/css/colors/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:36 +0330] "GET /plugins/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:36 +0330] "GET /.well-known/header.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:37 +0330] "GET /wordpress/wp-content/uploads/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:55:37 +0330] "GET /.well-known/pki-validation/server.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:37 +0330] "GET /autoload_classmap/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:37 +0330] "GET /wp-content/plugins/pwnd/1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:55:38 +0330] "GET /wp-content/plugins/ubh/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:38 +0330] "GET /wp-content/uploads/anas.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:38 +0330] "GET /wp-admin/css/colors/blue/shell.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:38 +0330] "GET /wp-content/plugins/erinyani/default.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:39 +0330] "GET /wp-includes/Text/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:55:39 +0330] "GET /xex.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:39 +0330] "GET /ar/wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:39 +0330] "GET /wp-includes/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:40 +0330] "GET /wp-content/plugins/pwnd/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:55:40 +0330] "GET /upload/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:40 +0330] "GET /wp-head.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:40 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:55:40 +0330] "GET /wp-content/upgrade/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:41 +0330] "GET /makeasmtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:55:41 +0330] "GET /wp-includes/wp-sup.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:41 +0330] "GET /wordpress/wp-includes/class-wp-http-ixr-client-view.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:41 +0330] "GET /images/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:42 +0330] "GET /wp-includes/widgets/class-t.api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:42 +0330] "GET /wp-content/edit.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:42 +0330] "GET /.well-known/info.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:42 +0330] "GET /wp-content/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:43 +0330] "GET /wp-admin/css/colors/blue/navi.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:43 +0330] "GET /wp-includes/css/dist/require-dynamic-blocks.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:43 +0330] "GET /xp.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:43 +0330] "GET /wp-content/languages/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:44 +0330] "GET /wp-content/bypass_1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:44 +0330] "GET /wp-admin/js/elementskit.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:44 +0330] "GET /admin/user_data.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:44 +0330] "GET /wp-includes/widgets/class-wp-widget-rss-database.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:45 +0330] "GET /.well-known/pki-validation/kur.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:45 +0330] "GET /click.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:45 +0330] "GET /wp-includes/class-wp-customize-manager-client.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:55:45 +0330] "GET /wp-includes/assets/script-modules-packages.min-boolean.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:46 +0330] "GET /wp-admin/css/colors/error.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:46 +0330] "GET /ALFA_DATA/alfacgiapi/all.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:55:46 +0330] "GET /wp-admin/images/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:46 +0330] "GET /.well-known/pki-validation/xmrlpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:55:47 +0330] "GET /wp-admin/maint/repairs.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:55:47 +0330] "GET /wp-includes/images/smilies/simi.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:47 +0330] "GET /wp-admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:47 +0330] "GET /wp-header.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:48 +0330] "GET /file.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:48 +0330] "GET /.tmb/doc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:48 +0330] "GET /wp-editor.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:55:48 +0330] "GET /wp-includes/style-engine-session.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:49 +0330] "GET /images/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:49 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/adminfusm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:49 +0330] "GET /adminfusm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:49 +0330] "GET /js/js1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:50 +0330] "GET /wp-includes/assets/wp-includes/assets/script-loader-packages.min.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:50 +0330] "GET /wp-includes/blocks/file/wp-style.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:50 +0330] "GET /images/habhan.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:50 +0330] "GET /wp-content/mu-plugins/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:55:50 +0330] "GET /wp-includes/IXR/class-IXR-cilent.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:51 +0330] "GET /wp-content/uploads/wp-cert.phtml HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:51 +0330] "GET /about/function.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:51 +0330] "GET /routes/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:51 +0330] "GET /wp-includes/images/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:52 +0330] "GET /wp-includes/PHPMailer/xleet.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:52 +0330] "GET /wp-admin/js/widgets/doc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:52 +0330] "GET /f35_SpaceTn.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:55:52 +0330] "GET /wp-admin/css/colors/sunrise/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:55:53 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/fixed.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:53 +0330] "GET /wp-admin/js/widgets/themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:53 +0330] "GET /wp-content/plugins/fix/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:55:53 +0330] "GET /wp-includes/category-double.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:54 +0330] "GET /wp-admin/maint/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:54 +0330] "GET /blog/signatur.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:54 +0330] "GET /wp-includes/assets/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:55:54 +0330] "GET /wp-includes/widgets/security.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:55 +0330] "GET /include/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:55 +0330] "GET /gm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:55 +0330] "GET /wp-includes/class-wp-language-pack.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:55 +0330] "GET /js/content-type.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:56 +0330] "GET /wp-includes/class-walker-comment-client.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:56 +0330] "GET /about/goods.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:56 +0330] "GET /file/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:56 +0330] "GET /function/goods.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:57 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:57 +0330] "GET /wp-content/upgrade/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:57 +0330] "GET /wp-includes/class-wp-network-query-stat.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:57 +0330] "GET /wp-content/themes/pridmag/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:58 +0330] "GET /plugin-install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:58 +0330] "GET /wp-includes/class-wp-session-tokens-https.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:58 +0330] "GET /wp-admin/js/load.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:58 +0330] "GET /images/firewall.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:59 +0330] "GET /wp-includes/images/crystal/lrs_dage.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:59 +0330] "GET /wp-content/upgrade/pdf.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:59 +0330] "GET /wp-includes/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:59 +0330] "GET /wp-content/item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:59 +0330] "GET /wp-includes/certificates/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:56:00 +0330] "GET /wp-includes/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:00 +0330] "GET /wp-includes/customize/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:00 +0330] "GET /css/fan.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:00 +0330] "GET /wp-admin/css/colors/blue/colors.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:01 +0330] "GET /images/mah.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:01 +0330] "GET /wp-content/waf_defender.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:56:01 +0330] "GET /wp-admin/css/colors/ectoplasm/content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:01 +0330] "GET /wp-content/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:02 +0330] "GET /wp-includes/js/thickbox/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:02 +0330] "GET /wp-content/content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:56:02 +0330] "GET /wp-content/themes/twentytwentyfour/icascreenshots.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:02 +0330] "GET /wp-content/upgrade/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:03 +0330] "GET /wp-includes/rk2.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:03 +0330] "GET /wp-admin/css/colors/ocean/alam.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:03 +0330] "GET /.well-known/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:03 +0330] "GET /b.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:04 +0330] "GET /wp-includes/certificates/past.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:04 +0330] "GET /wp-content/uploads/2021/faiyy.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:04 +0330] "GET /css/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:04 +0330] "GET /wp-content/plugins/pwnd/sst.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:05 +0330] "GET /wp-includes/edit-tags.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:05 +0330] "GET /wsax.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:05 +0330] "GET /bless.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:56:05 +0330] "GET /wp-content/uploads/system_cache.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:56:06 +0330] "GET /templates/beez3/dbcthbohhr.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:56:06 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/files.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:06 +0330] "GET /wp-content/themes/tflow/admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:56:06 +0330] "GET /wp-includes/css/dist/footer-default.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:07 +0330] "GET /wp-content/plugins/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:07 +0330] "GET /wp-includes/widgets/class-wp-widget-meta-request.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:07 +0330] "GET /wp-content/plugins/pwnd/cloud.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:07 +0330] "GET /wp-includes/css/dist/edit-widgets/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:56:08 +0330] "GET /wp-content/plugins/ubh/adminfus.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:08 +0330] "GET /.well-known/pki-validation/webdb.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:08 +0330] "GET /wp-includes/l10n/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:08 +0330] "GET /wp-admin/js/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:08 +0330] "GET /wp-admin/js/widgets/item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:09 +0330] "GET /uploads/xsec.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:09 +0330] "GET /images/Marvins.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:09 +0330] "GET /wp-content/plugins/pwnd-1/kurd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:09 +0330] "GET /wp-content/themes/tflow/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:10 +0330] "GET /wp-content/languages/radio.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:56:10 +0330] "GET /wp-content/uploads/fileman.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:10 +0330] "GET /wp-includes/widgets/wp-ss.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:10 +0330] "GET /wp-includes/IXR/xsec1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:56:11 +0330] "GET /admin.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:11 +0330] "GET /wp-admin/css/colors/hong1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:56:11 +0330] "GET /wp-admin/maint/byps.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:11 +0330] "GET /wp-includes/images/crystal/sad.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:56:12 +0330] "GET /wp-includes/assets/script-loader-packages.min.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:12 +0330] "GET /wp-content/themes/twentytwentyfour/patterns/content-type.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:12 +0330] "GET /wp-admin/network/class.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:12 +0330] "GET /wp-includes/class-phpmailer-beta.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:56:13 +0330] "GET /wp-includes/ms-file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:13 +0330] "GET /.well-known/acme-challenge/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:13 +0330] "GET /wp-includes/widgets/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:13 +0330] "GET /images/news_event/1.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:14 +0330] "GET /chosen.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:14 +0330] "GET /bs1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:14 +0330] "GET /wp-includes/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:14 +0330] "GET /wp-includes/network.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:56:15 +0330] "GET /page.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:15 +0330] "GET /wp-admin/includes/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:15 +0330] "GET /wp-content/uploads/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:15 +0330] "GET /wp-content/plugins/WordPressCore/include.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:16 +0330] "GET /wp-content/admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:16 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:16 +0330] "GET /assets/info.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:16 +0330] "GET /wp-includes/SimplePie/XML/content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:56:17 +0330] "GET /wp-includes/pomo/item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:17 +0330] "GET /wp-content/1.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:17 +0330] "GET /wp-admin/css/colors/blue/wp-atom.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:17 +0330] "GET /wp-includes/pomo/plugins.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:17 +0330] "GET /wp-includes/assets/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:18 +0330] "GET /.well-known/acme-challenge/gecko-old.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:56:18 +0330] "GET /wp-admin/css/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:18 +0330] "GET /images/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:18 +0330] "GET /wp-includes/widgets/class-wp-nav-widgets.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:19 +0330] "GET /x/test.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:19 +0330] "GET /wp-content/themes/wp-pridmag/init.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:19 +0330] "GET /wp-admin/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:19 +0330] "GET /wp-admin/css/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:20 +0330] "GET /wp-includes/sitemaps/providers/doc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:20 +0330] "GET /ws.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:20 +0330] "GET /wp-includes/rest-api/1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:56:20 +0330] "GET /wp-includes/fonts/class_api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:21 +0330] "GET /shop.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:21 +0330] "GET /wp-content/plugins/pwnd-1/dedi1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:21 +0330] "GET /wp-admin/js/widgets/setting.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:21 +0330] "GET /wp-includes/images/smilies/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:22 +0330] "GET /wp-admin/css/colors/light/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:22 +0330] "GET /wp-admin/user/header.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:56:22 +0330] "GET /wp-includes/IXR/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:22 +0330] "GET /wp-api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:23 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:56:23 +0330] "GET /css.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:56:23 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:23 +0330] "GET /wp-includes/class-wp-customize-manager-interpreter.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:24 +0330] "GET /wp-includes/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:24 +0330] "GET /images/fm.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:24 +0330] "GET /wp-includes/count.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:24 +0330] "GET /wp-error_log.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:25 +0330] "GET /assets/class_update_plugins.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:25 +0330] "GET /wp-admin/network/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:56:25 +0330] "GET /templates/beez5/error.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:25 +0330] "GET /wp-admin/network/admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:26 +0330] "GET /js/firewall.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:26 +0330] "GET /wp-includes/certificates/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:26 +0330] "GET /assets/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:26 +0330] "GET /wp-admin/js/file/incpb.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:26 +0330] "GET /images/stories/themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:27 +0330] "GET /wp-includes/theme-compat/footer-embed-function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:27 +0330] "GET /wp-includes/firewall.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:27 +0330] "GET /home/O-Simple.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:27 +0330] "GET /wp-includes/l10n/class-wp-translation-file-mo-event.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:28 +0330] "GET /wp-includes/vars-soap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:28 +0330] "GET /wp-content/themes/twentytwentytwo/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:28 +0330] "GET /style.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:28 +0330] "GET /files.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:29 +0330] "GET /wp-content/themes/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:29 +0330] "GET /wp-admin/css/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:29 +0330] "GET /saka.phP7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:29 +0330] "GET /wp-includes/id3/wp-work.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:30 +0330] "GET /wp-content/plugins/WordPressCore/gecko.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:56:30 +0330] "GET /baxa1.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:30 +0330] "GET /wp-includes/class-wp-taxonomy.editor.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:30 +0330] "GET /wp-content/plugins/pwnd/dedi1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:31 +0330] "GET /wp-includes/js/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:31 +0330] "GET /blog.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:56:31 +0330] "GET /about/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:56:31 +0330] "GET /wp-content/themes/pridmag/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:56:32 +0330] "GET /wp-admin/network/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:32 +0330] "GET /images/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:32 +0330] "GET /wp-includes/interactivity-api/interactivity-api-xml.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:32 +0330] "GET /js/mrx.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:56:33 +0330] "GET /wp-includes/colour.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:33 +0330] "GET /elp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:33 +0330] "GET /wp-includes/customize/class-wp-customize-background-position-control-variable.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:33 +0330] "GET /wp-includes/images/include.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:34 +0330] "GET /wp-content/themes/av.php.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:34 +0330] "GET /wp-content/plugins/pwnd-1/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:34 +0330] "GET /wp-includes/js/imgareaselect/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:34 +0330] "GET /upload/bilder/cong.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:35 +0330] "GET /fonts/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:35 +0330] "GET /wp-admin/css/colors/blue/pass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:35 +0330] "GET /entrepreneuse.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:56:35 +0330] "GET /wp-includes/l10n/class-wp-translations-interface.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:36 +0330] "GET /wp-includes/assets/about5.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:36 +0330] "GET /wp-admin/maint/lint-branch.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:56:36 +0330] "GET /wp-content/cong.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:56:36 +0330] "GET /js/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:37 +0330] "GET /.well-known/buy.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:37 +0330] "GET /index/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:37 +0330] "GET /wp-includes/ID3/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:37 +0330] "GET /function/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:37 +0330] "GET /wp-content/themes/tflow/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:38 +0330] "GET /wp-includes/js/dist/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:38 +0330] "GET /testt.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:38 +0330] "GET /wp-content/uploads/goods.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:38 +0330] "GET /wp-admin/js/sad.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:39 +0330] "GET /wp-includes/sitemaps/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:39 +0330] "GET /wp-includes/assets/wp-includes/assets/script-loader-packages.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:39 +0330] "GET /web/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:39 +0330] "GET /wp-includes/SimplePie/login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:56:40 +0330] "GET /network.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:40 +0330] "GET /wp-admin/css/colors/blue/alfa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:40 +0330] "GET /wp-includes/sitemaps/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:56:40 +0330] "GET /wikindex.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:41 +0330] "GET /wp-content/plugins/seoo/alfa.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:56:41 +0330] "GET /wp-includes/SimplePie/Cache/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:56:41 +0330] "GET /wp-includes/css/dist/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:56:41 +0330] "GET /wp-content/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:42 +0330] "GET /wp-includes/customize/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:42 +0330] "GET /wp-includes/js/simi.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:42 +0330] "GET /wp-admin/images/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:42 +0330] "GET /wp-admin/css/colors/gold.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:43 +0330] "GET /wp-includes/Requests/Text/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:43 +0330] "GET /wp-content/mu-plugins/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:43 +0330] "GET /wp-includes/sitemaps/abcd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:56:43 +0330] "GET /wp-includes/ID3/rk2.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:44 +0330] "GET /wp-includes/widgets/class-wp-widget-search-interpreter.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:44 +0330] "GET /wp-admin/css/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:44 +0330] "GET /bitrix/admin/htmleditor2/natural.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:44 +0330] "GET /wp-content/plugins/pwnd/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:45 +0330] "GET /wp-includes/block-template-utils-other.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:45 +0330] "GET /wp-content/alam.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:45 +0330] "GET /css/adminfusm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:45 +0330] "GET /wp-includes/sodium_compat/lib/widget-group.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:46 +0330] "GET /wp-content/raw.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:46 +0330] "GET /wp-includes/js/jcrop/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:46 +0330] "GET /wp-admin/includes/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:46 +0330] "GET /wp-includes/customize/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:46 +0330] "GET /wp-content/uploads/2021/wp-works.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:47 +0330] "GET /wp-admin/media-new.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:47 +0330] "GET /media-new.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:47 +0330] "GET /js/class_api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:47 +0330] "GET /wp-content/uploads/2021/themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:48 +0330] "GET /admin/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:48 +0330] "GET /wp-includes/plugin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:48 +0330] "GET /wp-includes/class-wp-scripts-query.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:48 +0330] "GET /wp-admin/js/item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:56:49 +0330] "GET /pages.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:56:49 +0330] "GET /wp-includes/ID3/module.audio-license.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:49 +0330] "GET /wp-content/themes/classwithtostring.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:49 +0330] "GET /uploads/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:50 +0330] "GET /assets/js/doc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:50 +0330] "GET /assets/comfunctions.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:56:50 +0330] "GET /wp-includes/class-wp-error-module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:56:50 +0330] "GET /css/adminfus.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:51 +0330] "GET /adminfus.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:51 +0330] "GET /wp-includes/css/litespeed.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:51 +0330] "GET /images/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:56:51 +0330] "GET /wp-admin/setup-config.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:52 +0330] "GET /wp-includes/css/dist/alam.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:52 +0330] "GET /cong.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:52 +0330] "GET /wp-includes/block-bindings/imagess.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:56:52 +0330] "GET /wp-content/plugins/pwnd/adminfus.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:53 +0330] "GET /wp-includes/default-filters-edit.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:53 +0330] "GET /css/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:53 +0330] "GET /assets/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:53 +0330] "GET /autoload_classmap/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:54 +0330] "GET /wp-configs.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:56:54 +0330] "GET /wp-includes/Requests/Auth/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:54 +0330] "GET /wp-admin/js/widgets/bless2.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:54 +0330] "GET /wp-admin/network/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:55 +0330] "GET /wp-admin/item.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:55 +0330] "GET /wp-includes/Text/Diff/Engine/theme.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:55 +0330] "GET /.well-known/acme-challenge/mah.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:55 +0330] "GET /wp-includes/ID3/shell.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:56:56 +0330] "GET /wp-includes/customize/class-wp-customize-selective-refresh-library.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:56 +0330] "GET /ms-users.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:56 +0330] "GET /wp-admin/js/cc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:56 +0330] "GET /wp-includes/Requests/library/wp-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:56 +0330] "GET /wp-includes/interactivity-api/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:57 +0330] "GET /css/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:57 +0330] "GET /wp-content/plugins/classic-editor/alam.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:57 +0330] "GET /wordpress/wp-admin/includes/wordpress/wp-admin/includes/admin-filters.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:56:57 +0330] "GET /assets/content.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:58 +0330] "GET /fm.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:56:58 +0330] "GET /wp-content/goods.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:56:58 +0330] "GET /wp-includes/wp-2019.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:58 +0330] "GET /wp-includes/SimplePie/info.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:59 +0330] "GET /assets/images/cloud.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:56:59 +0330] "GET /wp-includes/log.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:56:59 +0330] "GET /wp-includes/assets/script-loader-react-refresh-runtime-num.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:56:59 +0330] "GET /wp-includes/assets/script-loader-react-refresh-entry.min-object.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:00 +0330] "GET /wp-includes/aw.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:57:00 +0330] "GET /update/gely.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:00 +0330] "GET /uploads/c99shell.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:57:00 +0330] "GET /wp-content/themes/pridmag/admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:01 +0330] "GET /uploads/lala.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:01 +0330] "GET /wp-includes/IXR/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:57:01 +0330] "GET /wp-includes/css/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:01 +0330] "GET /wp-content/plugins/wp-theme-editor/include.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:02 +0330] "GET /top.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:57:02 +0330] "GET /wp-includes/css/dist/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:57:02 +0330] "GET /wp-includes/style-engine/dedi1.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:02 +0330] "GET /wp-admin/css/adminfusm.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:03 +0330] "GET /wp-content/click.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:03 +0330] "GET /wp-includes/template-less.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:57:03 +0330] "GET /wp-includes/pomo/alfa-rex.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:03 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/abcd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:04 +0330] "GET /wp-admin/css/colors/blue/admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:57:04 +0330] "GET /retu11.PhP7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:04 +0330] "GET /wp-content/themes/twentytwentytwo/bypass.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:57:04 +0330] "GET /wp-admin/css/elementskit.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:05 +0330] "GET /js/1.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:05 +0330] "GET /wp-content/themes/twentytwentyfour/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:05 +0330] "GET /wp-includes/assets/min.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:05 +0330] "GET /wp-includes/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:05 +0330] "GET /backup/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:06 +0330] "GET /wp-content/uploads/uploads.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:06 +0330] "GET /wp-includes/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:57:06 +0330] "GET /wp-content/themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:06 +0330] "GET /wp-includes/block-patterns/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:07 +0330] "GET /worm0.PhP7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" 37.120.207.174 - - [06/Nov/2025:15:57:07 +0330] "GET /wp-includes/load.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:57:07 +0330] "GET /wp-includes/ID3/chosen.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:07 +0330] "GET /wp-includes/class-wp-theme-float.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:08 +0330] "GET /images/c99.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:57:08 +0330] "GET /wp-content/plugins/core-plugin/waf_defender.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:57:08 +0330] "GET /wp-content/themes/twentytwentytwo/as.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:08 +0330] "GET /wp-includes/widgets/wp-style.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 37.120.207.174 - - [06/Nov/2025:15:57:09 +0330] "GET /setup-config.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:09 +0330] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:09 +0330] "GET /wp-content/uploads/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:57:09 +0330] "GET /img/prettyPhoto/dark_square/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:10 +0330] "GET /type.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:10 +0330] "GET /wp-includes/block-bindings/admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:10 +0330] "GET /wp-includes/PHPMailer/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:10 +0330] "GET /as/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:11 +0330] "GET /wp-includes/theme-compat/db.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:11 +0330] "GET /wp-admin/maint/flex.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" 37.120.207.174 - - [06/Nov/2025:15:57:11 +0330] "GET /css/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:11 +0330] "GET /css/hekokstyle.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:12 +0330] "GET /wp-admin/user/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" 37.120.207.174 - - [06/Nov/2025:15:57:12 +0330] "GET /files/shares/403ws.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:57:12 +0330] "GET /goat.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" 37.120.207.174 - - [06/Nov/2025:15:57:12 +0330] "GET /images/fix.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:13 +0330] "GET /wp-content/themes/tflow/adminfus.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:57:13 +0330] "GET /files.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:13 +0330] "GET /wp-includes/assets/system.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:57:13 +0330] "GET /wp-includes/l10n/class-wp-translations-library.php%20 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:14 +0330] "GET /wp-includes/block-bindings/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:57:14 +0330] "GET /images/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:56 +0330] "GET /wp-admin/network/atomlib.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:56 +0330] "GET /.well-known/install.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:56 +0330] "GET /hehe.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:57 +0330] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:57 +0330] "GET /css/slider.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:57 +0330] "GET /dir.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:57 +0330] "GET /wp-includes/css/atomlib.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:58 +0330] "GET /wp-content/style.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:58 +0330] "GET /libraries/phpmailer/updates.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:58 +0330] "GET /nf_tracking.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:54:58 +0330] "GET /wp-admin/css/about.php7 HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:54:59 +0330] "GET /filefuns.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:54:59 +0330] "GET /.well-known/pki-validation/class_api.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:59 +0330] "GET /l.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:54:59 +0330] "GET /repeater.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:28 +0330] "GET /wp-content/plugins/ioxi/ioxi/dropdown.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:28 +0330] "GET /memberfuns.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:28 +0330] "GET /infos.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:28 +0330] "GET /modules/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:29 +0330] "GET /wp-content/x.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 37.120.207.174 - - [06/Nov/2025:15:55:29 +0330] "GET /wp-content/wp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0" 37.120.207.174 - - [06/Nov/2025:15:55:29 +0330] "GET /options-writing.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" 37.120.207.174 - - [06/Nov/2025:15:55:29 +0330] "GET /options-reading.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:30 +0330] "GET /wsad.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:30 +0330] "GET /nation.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:30 +0330] "GET /wp-includes/js/codemirror/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95" 37.120.207.174 - - [06/Nov/2025:15:55:30 +0330] "GET /wp-includes/wp_class_datlib.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:55:31 +0330] "GET /wp-includes/js/tinymce/langs/about.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" 37.120.207.174 - - [06/Nov/2025:15:55:31 +0330] "GET /autoload_classmap/wso.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:31 +0330] "GET /wp-atomx.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" 37.120.207.174 - - [06/Nov/2025:15:55:31 +0330] "GET /admin-footer.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:55:32 +0330] "GET /wp-admin/maint/wp-conflg.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 194.165.16.8 - - [06/Nov/2025:16:12:02 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0" 206.168.34.51 - - [06/Nov/2025:16:35:59 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 37.120.207.174 - - [06/Nov/2025:15:57:14 +0330] "GET /wp-content/plugins/linkpreview/av.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:14 +0330] "GET /wp-includes/customize/class-wp-customize-upload-control-cookie.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:14 +0330] "GET /wp-includes/ID3/simi.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:15 +0330] "GET /wp-includes/class-wp-taxonomy-sample.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" 37.120.207.174 - - [06/Nov/2025:15:57:15 +0330] "GET /img/chat-search.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:15 +0330] "GET /wp-includes/css/dist/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:15 +0330] "GET /wp-includes/js/dist/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 37.120.207.174 - - [06/Nov/2025:15:57:16 +0330] "GET /wp-includes/assets/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:16 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:16 +0330] "GET /wp-content/plugins/erinyani/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:16 +0330] "GET /wp-includes/l10n/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0" 37.120.207.174 - - [06/Nov/2025:15:57:17 +0330] "GET /wp-content/uploads/2023/11/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 37.120.207.174 - - [06/Nov/2025:15:57:17 +0330] "GET /wp-includes/sodium_compat/lib/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; rv:11.0) like Gecko" 196.251.88.246 - - [06/Nov/2025:17:14:49 +0330] "GET /userfuns.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 43.156.204.134 - - [06/Nov/2025:17:23:00 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 194.165.16.8 - - [06/Nov/2025:17:33:15 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" 146.70.138.204 - - [06/Nov/2025:17:59:50 +0330] "GET /bolt.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:00:30 +0330] "GET /wp-admin/zwso.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:00:56 +0330] "GET /flower.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:01:20 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:01:55 +0330] "GET /tmb/file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:02:19 +0330] "GET /wp-content/plugins/hellopress/wp_mna.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:02:25 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:02:57 +0330] "GET /wp-admin/admin-ajax.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:03:30 +0330] "GET /abcd.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:03:42 +0330] "GET /wp-content/plugins/linkpreview/ HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:29:34 +0330] "GET /file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:30:34 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:33:08 +0330] "GET /file88.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:31:37 +0330] "GET /file5.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 146.70.138.204 - - [06/Nov/2025:18:34:20 +0330] "GET /NewFile.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:00:23 +0330] "GET /wp-includes/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:00:39 +0330] "GET /504.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:10:59 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:14:46 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:10:38 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:11:06 +0330] "GET /xl2023x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:12:15 +0330] "GET /xxl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:13:16 +0330] "GET /x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:14:42 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:14:46 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:14:47 +0330] "GET /xl2023x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:19:14:52 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:47:45 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:47:46 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:48:09 +0330] "GET /wp-content/plugins/deu/ms.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:47:49 +0330] "GET /file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:47:52 +0330] "GET /wp-content/akp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:47:53 +0330] "GET /wp-content/plugins/hanau/akc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:48:04 +0330] "GET /aw.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:48:05 +0330] "GET /wp-content/plugins/geu/geu.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:20:48:10 +0330] "GET /wp-content/plugins/view-ad/ms.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:21:23:47 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:21:26:47 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:21:39:15 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:03:46 +0330] "GET /wp-content/plugins/google-seo-rank/module.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:06:27 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:07:14 +0330] "GET /first.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:07:18 +0330] "GET /504.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:07:24 +0330] "GET /log-mama/function.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:07:37 +0330] "GET /admin.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:07:49 +0330] "GET /bk/index.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.107 Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:08:38 +0330] "GET /file.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:08:43 +0330] "GET /wp-content/akp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:08:43 +0330] "GET /wp-content/plugins/hanau/akc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:11:21 +0330] "GET /smtp.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 196.251.88.40 - - [06/Nov/2025:22:17:22 +0330] "GET /userfuns.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:17:29 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:17:35 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:08:28 +0330] "GET /wp-content/plugins/work-list/lang.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:08:28 +0330] "GET /ioxi-o.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:08:36 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:08:37 +0330] "GET /file17.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:08:44 +0330] "GET /aw.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:11:40 +0330] "GET /wp-includes/Text/mar.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 41.141.91.154 - - [06/Nov/2025:22:11:42 +0330] "GET /themes.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0" 41.141.91.154 - - [06/Nov/2025:22:23:23 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:30:58 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:31:01 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:31:29 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:31:46 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:32:27 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:32:51 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:32:57 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:04 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:04 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:05 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:25 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:33 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:53 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:57 +0330] "GET /uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:01 +0330] "GET /upload/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:02 +0330] "GET /admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:06 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:31:46 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:31:50 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:31:51 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:01 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:02 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:07 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:22 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:23 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:26 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:28 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:33:30 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:20 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:22 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:24 +0330] "GET /assets/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:29 +0330] "GET /vendor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:07 +0330] "GET /admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:18 +0330] "GET /images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:18 +0330] "GET /assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:25 +0330] "GET /Public/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:29 +0330] "GET /local/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:38 +0330] "GET /template/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:44 +0330] "GET /files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:46 +0330] "GET /admin/editor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:03 +0330] "GET /Assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:23 +0330] "GET /wp-includes/assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:32 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:36 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:39 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:42 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:59 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:30 +0330] "GET /modules/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:36 +0330] "GET /Site/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:37 +0330] "GET /system/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:34:42 +0330] "GET /shop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:03 +0330] "GET /images/stories/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:06 +0330] "GET /plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:51 +0330] "GET /Mshell.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:35:57 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:36:07 +0330] "GET /wp-includes/SimplePie/Content/Type/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:36:12 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:36:30 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:08 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:25 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:44 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:46 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:36:01 +0330] "GET /wp-includes/SimplePie/Cache/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:36:11 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:36:32 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:36:52 +0330] "GET /wp-includes/Requests/Proxy/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:37:29 +0330] "GET /wp-includes/Requests/Response/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:37:57 +0330] "GET /wp-includes/Requests/Transport/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:37:57 +0330] "GET /wp-includes/Requests/Utility/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:37:58 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:06 +0330] "GET /wp-includes/Requests/Exception/HTTP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:09 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:39 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:40 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:38:42 +0330] "GET /wp-includes/Requests/Exception/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:05 +0330] "GET /wp-includes/Text/Diff/Engine/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:16 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:17 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:20 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:29 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:37 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:41 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:46 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:01 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:14 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:15 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:19 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:21 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:39 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:39:42 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:40:05 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:40:08 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:40:35 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:40:36 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 95.217.109.26 - - [06/Nov/2025:22:41:37 +0330] "GET /robots.txt HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)" 41.141.91.154 - - [06/Nov/2025:22:41:40 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:43 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:44 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:49 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:50 +0330] "GET /components/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:54 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:56 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:58 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:02 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:20 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 95.217.109.26 - - [06/Nov/2025:22:41:40 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)" 41.141.91.154 - - [06/Nov/2025:22:41:41 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:46 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:52 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:53 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:53 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:55 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:41:57 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:24 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:26 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:29 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:43 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:22 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:23 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:22:42:31 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:02:54 +0330] "GET /.well-known/acme-challenge/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:24 +0330] "GET /wp-content/themes/gaukingo/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:25 +0330] "GET /wp-content/plugins/seoplugins/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:32 +0330] "GET /wp-content/plugins/ioptimization/IOptimize.php?rchk HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:35 +0330] "GET /wp-content/plugins/ioptimizations/IOptimizes.php?hamlorszd HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:39 +0330] "GET /wp-content/uploads/wp_live_chat/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:47 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/a57bze8931.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:57 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:07 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:15 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:32 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/a57bze8931.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:36 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:37 +0330] "GET /wp-content/plugins/formcraft/file-upload/server/php/files/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:45 +0330] "GET /wp-content/plugins/formcraft/file-upload/server/php/files/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:54 +0330] "GET /wp-content/plugins/formcraft/file-upload/server/php/files/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:09:06 +0330] "GET /wp-content/plugins/ioptimization/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:09:13 +0330] "GET /wp-content/plugins/ioptimization/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:09:14 +0330] "GET /wp-content/plugins/apikey/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:02:53 +0330] "GET /.well-known/pki-validation/cloud.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:14 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:22 +0330] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:23 +0330] "GET /wp-content/plugins/linkpreview/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:07:59 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:03 +0330] "GET /wp-content/plugins/wp-file-manager/lib/files/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:08 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:17 +0330] "GET /wp-content/plugins/superstorefinder-wp/ssf-wp-admin/pages/SSF_WP_UPLOADS_PATH/csv/import/abruzi.php4 HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:46 +0330] "GET /wp-content/plugins/formcraft/file-upload/server/php/files/abruzi.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:08:54 +0330] "GET /wp-content/plugins/ioptimization/king.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:09:04 +0330] "GET /wp-content/plugins/ioptimization/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [06/Nov/2025:23:09:25 +0330] "GET /wp-content/plugins/apikey/xo.php HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:12:33 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:12:34 +0330] "GET /wp-includes/Text/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:12:32 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:12:33 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:12:42 +0330] "GET /wp-includes/css/dist/niil.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:30 +0330] "GET /wp-includes/Text/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:45 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:46 +0330] "GET /wp-includes/images/wp-login.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:24 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:26 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:30 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:32 +0330] "GET /wp-includes/css/dist/niil.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:35 +0330] "GET /asd.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:36 +0330] "GET /1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:39 +0330] "GET /ws.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:41 +0330] "GET /wp-includes/css/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:42 +0330] "GET /cgi-bin/wp-login.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:42 +0330] "GET /wp-content/cong.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:47 +0330] "GET /wp-includes/Requests/network.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:55 +0330] "GET /wp-content/radio.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:08 +0330] "GET /hehehehe.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:09 +0330] "GET /simple.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:17 +0330] "GET /wp-includes/fonts/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:18 +0330] "GET /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:28 +0330] "GET /wp-admin/maint/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:36:56 +0330] "GET /wp-admin/dropdown.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:04 +0330] "GET /login.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:18 +0330] "GET /wp-content/admin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:19 +0330] "GET /atomlib.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:20 +0330] "GET /lv.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:24 +0330] "GET /wp-includes/Text/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:25 +0330] "GET /content.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:25 +0330] "GET /.well-known/acme-challenge/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:26 +0330] "GET /goat.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:27 +0330] "GET /.well-known/acme-challenge/admin.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:27 +0330] "GET /wp-content/uploads/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 41.141.91.154 - - [07/Nov/2025:00:37:30 +0330] "GET /dropdown.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:30:24 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:30:25 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:30:42 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:30:43 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:31:25 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:31:26 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:31:46 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:09 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:15 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:17 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:27 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:05 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:07 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:09 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:11 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:29:49 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:29:50 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:30:27 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:30:58 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:09 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:11 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:18 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:22 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:32:45 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:10 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:15 +0330] "GET /upload/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:20 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:35 +0330] "GET /images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:39 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:43 +0330] "GET /assets/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:13 +0330] "GET /uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:16 +0330] "GET /admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:28 +0330] "GET /admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:37 +0330] "GET /assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:33:38 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:34:01 +0330] "GET /Public/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:34:08 +0330] "GET /vendor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:07 +0330] "GET /system/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:12 +0330] "GET /template/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:13 +0330] "GET /shop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:15 +0330] "GET /admin/editor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:59 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:00 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:08 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:09 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:34:30 +0330] "GET /local/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:02 +0330] "GET /Site/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:14 +0330] "GET /files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:15 +0330] "GET /include/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:16 +0330] "GET /Assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:17 +0330] "GET /images/stories/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:25 +0330] "GET /plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:27 +0330] "GET /php/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:35:48 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:00 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:10 +0330] "GET /wp-includes/SimplePie/Cache/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:27 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:31 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:32 +0330] "GET /wp-includes/Requests/Cookie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:34 +0330] "GET /wp-includes/Requests/Proxy/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:28 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:30 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:12 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:38 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:44 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:46 +0330] "GET /wp-includes/Requests/Exception/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:54 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:38:42 +0330] "GET /wp-includes/Text/Diff/Engine/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:23 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:30 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:46 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:47 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:04 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:04 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:05 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:36:34 +0330] "GET /wp-includes/Requests/Response/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:05 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:09 +0330] "GET /wp-includes/Requests/Exception/HTTP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:10 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:39 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:37:44 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:38:46 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:38:47 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:15 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:16 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:21 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:23 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:25 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:39:29 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:06 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:07 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:10 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:30 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:45 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:49 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:06 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [07/Nov/2025:01:41:09 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [07/Nov/2025:01:41:09 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 45.80.158.88 - - [07/Nov/2025:01:41:09 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:14 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:18 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:44 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:44 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:47 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:48 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:08 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:09 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:26 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:46 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:40:50 +0330] "GET /components/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:05 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [07/Nov/2025:01:41:09 +0330] "POST /wp-plain.php HTTP/1.1" 301 795 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [07/Nov/2025:01:41:09 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.80.158.88 - - [07/Nov/2025:01:41:10 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:38 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:40 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:47 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:54 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:42:03 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:42:04 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:41:50 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:43:20 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:43:43 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:42:04 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:43:51 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:44:06 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:44:30 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:44:46 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:45:03 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:45:24 +0330] "GET /wp-content/themes/classic/inc/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:45:26 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:46:16 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:46:17 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:46:22 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:46:22 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:46:27 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:46:47 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:21 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:25 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:27 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:28 +0330] "GET /uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:44:28 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:45:31 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:45:56 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:45:57 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:45:59 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:02 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:18 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:18 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:30 +0330] "GET /admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:48:31 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:48:40 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:48:40 +0330] "GET /assets/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:49:37 +0330] "GET /Site/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:49:42 +0330] "GET /template/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:06 +0330] "GET /images/stories/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:30 +0330] "GET /upload/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:34 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:47:35 +0330] "GET /admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:48:41 +0330] "GET /Public/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:48:49 +0330] "GET /vendor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:49:22 +0330] "GET /modules/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:49:38 +0330] "GET /system/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:49:43 +0330] "GET /shop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:01 +0330] "GET /files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:02 +0330] "GET /admin/editor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:03 +0330] "GET /include/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:04 +0330] "GET /Assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:36 +0330] "GET /wp-includes/assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:09 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:49 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:36 +0330] "GET /php/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:37 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:50:53 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:08 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:10 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:11 +0330] "GET /wp-includes/SimplePie/Cache/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:50 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:51 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:52 +0330] "GET /wp-includes/Requests/Cookie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:16 +0330] "GET /wp-includes/Requests/Response/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:20 +0330] "GET /wp-includes/Requests/Utility/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:22 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:52 +0330] "GET /wp-includes/Requests/Exception/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:03 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:08 +0330] "GET /wp-includes/Text/Diff/Engine/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:51:49 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:09 +0330] "GET /wp-includes/Requests/Proxy/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:18 +0330] "GET /wp-includes/Requests/Transport/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:31 +0330] "GET /wp-includes/Requests/Exception/HTTP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:32 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:34 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:50 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:51 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:52:51 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:02 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:07 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:43 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:44 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:55 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:56 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:40 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:53:56 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:54:00 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:54:17 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:55:28 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:55:30 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:55:37 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:55:52 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:56:14 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:56:19 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:56:19 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:56:24 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:21 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:23 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:25 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:54:51 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:56:11 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:56:12 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:56:17 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:56:18 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:18 +0330] "GET /components/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:19 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:20 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:42 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:43 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:48 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:54 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:26 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:44 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:45 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:46 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:49 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:52 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:01:57:55 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 158.94.208.149 - - [07/Nov/2025:02:09:32 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 105.159.242.18 - - [07/Nov/2025:02:13:40 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:13:41 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:13:43 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:13:51 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:13:59 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:02 +0330] "GET /wp-content/themes/classic/inc/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:11 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:19 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:23 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:37 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:38 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:47 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:50 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:51 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:13:32 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:00 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:01 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:03 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:15 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:20 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:22 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:33 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:47 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:48 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:14:49 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:15:08 +0330] "GET /uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:15:12 +0330] "GET /upload/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:11 +0330] "GET /admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:40 +0330] "GET /vendor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:15:07 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:20 +0330] "GET /images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:24 +0330] "GET /assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:25 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:33 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:34 +0330] "GET /assets/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:36 +0330] "GET /Public/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:56 +0330] "GET /local/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:16:58 +0330] "GET /modules/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:17:15 +0330] "GET /system/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:17:47 +0330] "GET /files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:02 +0330] "GET /admin/editor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:28 +0330] "GET /plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:29 +0330] "GET /php/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:32 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:06 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:09 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:10 +0330] "GET /wp-includes/SimplePie/Cache/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:15 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:18 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:22 +0330] "GET /wp-includes/Requests/Cookie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:26 +0330] "GET /wp-includes/Requests/Proxy/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:41 +0330] "GET /wp-includes/Requests/Response/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:55 +0330] "GET /wp-includes/Requests/Utility/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:16 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:17:46 +0330] "GET /shop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:03 +0330] "GET /include/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:27 +0330] "GET /images/stories/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:30 +0330] "GET /wp-includes/assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:34 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:41 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:18:50 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:14 +0330] "GET /wp-includes/SimplePie/Content/Type/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:17 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:20 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:19:42 +0330] "GET /wp-includes/Requests/Transport/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:39 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:43 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:44 +0330] "GET /wp-includes/Requests/Exception/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:46 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:24 +0330] "GET /wp-includes/Requests/Exception/HTTP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:27 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:31 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:41 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:42 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:47 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:18 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:26 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:29 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:32 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:34 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:53 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:57 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:02 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:04 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:48 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:49 +0330] "GET /wp-includes/Text/Diff/Engine/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:53 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:55 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:20:55 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:00 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:02 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:23 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:51 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:21:57 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:01 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:19 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:22 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:29 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:33 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:37 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:41 +0330] "GET /components/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:43 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:59 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:23:36 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:23:44 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:09 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:10 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:12 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:13 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:22 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:23 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:35 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:22:37 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:23:17 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:23:21 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:23:21 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:23:29 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:08 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:11 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:12 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:02:24:14 +0330] "GET /wp-admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 194.165.16.8 - - [07/Nov/2025:03:02:47 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0" 105.159.242.18 - - [07/Nov/2025:03:26:24 +0330] "GET /wp-includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:27 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:29 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:31 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:32 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:34 +0330] "GET /wp-content/themes/classic/inc/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:35 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:36 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:38 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:38 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:40 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:56 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:59 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:01 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:02 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:16 +0330] "GET /wp-content/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:25 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:31 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:33 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:26:58 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:00 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:15 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:43 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:52 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:00 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:24 +0330] "GET /admin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:24 +0330] "GET /images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:27 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:30 +0330] "GET /Public/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:32 +0330] "GET /vendor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:34 +0330] "GET /.well-known/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:42 +0330] "GET /cgi-bin/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:27:44 +0330] "GET /.well-knownold/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:04 +0330] "GET /uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:05 +0330] "GET /upload/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:06 +0330] "GET /admin/uploads/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:25 +0330] "GET /assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:29 +0330] "GET /upload/image/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:30 +0330] "GET /assets/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:45 +0330] "GET /Site/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:28 +0330] "GET /images/stories/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:28 +0330] "GET /plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:29 +0330] "GET /php/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:30 +0330] "GET /wp-includes/assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:33 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:33 +0330] "GET /local/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:28:41 +0330] "GET /modules/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:17 +0330] "GET /shop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:21 +0330] "GET /files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:23 +0330] "GET /admin/editor/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:24 +0330] "GET /include/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:25 +0330] "GET /Assets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:31 +0330] "GET /wp-includes/Text/Diff/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:36 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:40 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:42 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:42 +0330] "GET /wp-includes/SimplePie/Cache/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:45 +0330] "GET /wp-includes/SimplePie/Content/Type/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:00 +0330] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:01 +0330] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:01 +0330] "GET /wp-includes/Requests/Cookie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:25 +0330] "GET /wp-includes/Requests/Response/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:29 +0330] "GET /wp-includes/Requests/Transport/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:34 +0330] "GET /wp-includes/Requests/Exception/HTTP/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:45 +0330] "GET /wp-includes/js/crop/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:54 +0330] "GET /wp-includes/images/crystal/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:56 +0330] "GET /wp-includes/images/media/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:57 +0330] "GET /wp-includes/images/smilies/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:14 +0330] "GET /wp-includes/rest-api/search/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:23 +0330] "GET /wp-includes/Requests/Auth/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:23 +0330] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:25 +0330] "GET /wp-includes/sitemaps/providers/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:35 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:36 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:52 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:34 +0330] "GET /wp-includes/Text/Diff/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:47 +0330] "GET /wp-includes/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:29:58 +0330] "GET /wp-includes/SimplePie/Content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:33 +0330] "GET /wp-includes/Requests/Utility/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:33 +0330] "GET /wp-includes/js/codemirror/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:30:58 +0330] "GET /wp-includes/images/wlw/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:22 +0330] "GET /wp-includes/Requests/Exception/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:34 +0330] "GET /wp-includes/Text/Diff/Engine/Engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:34 +0330] "GET /wp-includes/customize/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:40 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:45 +0330] "GET /wp-includes/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:46 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:31:50 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:00 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:20 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:38 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:43 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:46 +0330] "GET /wp-includes/Text/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:47 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:55 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:12 +0330] "GET /sites/default/files/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:24 +0330] "GET /components/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:33 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:35 +0330] "GET /wp-includes/js/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:11 +0330] "GET /wp-admin/images/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:11 +0330] "GET /wp-admin/maint/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:13 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:18 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:29 +0330] "GET /wp-content/plugins/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:44 +0330] "GET /wp-content/themes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:42 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:44 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:44 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:32:57 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:01 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:08 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:10 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:20 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:22 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:36 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:33:51 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:09 +0330] "GET /wp-admin/css/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:19 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:28 +0330] "GET /wp-content/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:18 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:34:45 +0330] "GET /wp-admin/includes/ HTTP/1.1" 301 795 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:21 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:29 +0330] "GET /x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:32 +0330] "GET /xl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:38 +0330] "GET /wp-includes/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:24 +0330] "GET /xl2023x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:26 +0330] "GET /xxl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:36 +0330] "GET /wp-admin/xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:39 +0330] "GET /.well-known/acme-challenge/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:38:43 +0330] "GET /wp-admin/includes/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:03:39:18 +0330] "GET /wp-admin/maint/iR7SzrsOUEP.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 2.58.113.196 - - [07/Nov/2025:03:41:30 +0330] "GET /wp-links-opml.php HTTP/1.1" 301 795 "-" "-" 105.159.242.18 - - [07/Nov/2025:04:29:20 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:04:29:24 +0330] "GET /xl2023.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:04:29:26 +0330] "GET /xl2023x.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:04:29:26 +0330] "GET /xxl.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 180.242.130.29 - - [07/Nov/2025:04:53:33 +0330] "GET /wp-content/plugins/wps-hide-login/wps-hide-login.php HTTP/1.1" 301 795 "-" "Mozilla/5.0" 105.159.242.18 - - [07/Nov/2025:05:47:56 +0330] "GET /xleet.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 62.60.130.228 - - [07/Nov/2025:06:05:17 +0330] "GET /wp-login.php HTTP/1.1" 301 795 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.85 Safari/537.36" 194.165.16.8 - - [07/Nov/2025:06:06:07 +0330] "POST /xmlrpc.php HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0" 103.146.17.223 - - [07/Nov/2025:06:16:41 +0330] "GET /.well-known/pki-validation/xmrlpc.php?p= HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 43.130.16.140 - - [07/Nov/2025:08:08:32 +0330] "GET / HTTP/1.1" 301 795 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 105.159.242.18 - - [07/Nov/2025:08:09:09 +0330] "GET /wp-includes/rest-api/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:11 +0330] "GET /wp-content/languages/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:19 +0330] "GET /wp-includes/css/dist/niil.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:20 +0330] "GET /asd.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:37 +0330] "GET /ws.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:38 +0330] "GET /cgi-bin/wp-login.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:39 +0330] "GET /wp-content/cong.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:14 +0330] "GET /wp-content/banners/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:18 +0330] "GET /wp-includes/Text/about.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:36 +0330] "GET /1.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:37 +0330] "GET /wp-includes/css/index.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 105.159.242.18 - - [07/Nov/2025:08:09:40 +0330] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 795 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.167.150.158 - - [07/Nov/2025:09:02:04 +0330] "GET /wp-includes/js/jquery/jquery.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" 103.167.150.158 - - [07/Nov/2025:09:01:57 +0330] "GET /media/system/js/core.js HTTP/1.1" 301 795 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36"
| ver. 1.4 |
Github
|
.
| PHP 8.1.33 | Генерация страницы: 0.04 |
proxy
|
phpinfo
|
Настройка