43.167.241.46 - - [04/Nov/2025:15:41:24 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 198.199.77.16 - - [04/Nov/2025:16:34:09 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:01 +0330] "GET /sts.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:02 +0330] "GET /wp-hoard.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:05 +0330] "GET /priv8.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:08 +0330] "GET /wp-post-editor.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:12 +0330] "GET /classwithtostring.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:15 +0330] "GET /admin.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:18 +0330] "GET /wp-header.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:20 +0330] "GET /radio.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:21 +0330] "GET /cong.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:22 +0330] "GET /options.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:24 +0330] "GET /wp-content/index.php?x=ooo HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:25 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:26 +0330] "GET /sts.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:28 +0330] "GET /wp-hoard.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:29 +0330] "GET /1index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:31 +0330] "GET /11index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:04 +0330] "GET /wp-l0gin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:10 +0330] "GET /404.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:12 +0330] "GET /users.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:13 +0330] "GET /wp-head.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:16 +0330] "GET /about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:17 +0330] "GET /dropdown.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:21 +0330] "GET /simple.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:25 +0330] "GET /wp-admin/options.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:41 +0330] "GET /doc.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:44 +0330] "GET /alwso.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:45 +0330] "GET /ups.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:49 +0330] "GET /sym.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:53 +0330] "GET /fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:59 +0330] "GET /wp-blog.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:01 +0330] "GET /b.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:06 +0330] "GET /shx.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:10 +0330] "GET /a.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:31 +0330] "GET /2index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:32 +0330] "GET /3index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:35 +0330] "GET /wp_wrong_datlib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:37 +0330] "GET /wp-adminincludesclass-wp-media-list-data.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:38 +0330] "GET /autoload_classmap.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:39 +0330] "GET /wso.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:42 +0330] "GET /stindex.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:46 +0330] "GET /media-admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:50 +0330] "GET /sym403.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:54 +0330] "GET /symlink.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:55 +0330] "GET /shell.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:56 +0330] "GET /1.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:07:58 +0330] "GET /data.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:05 +0330] "GET /c.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:08 +0330] "GET /alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:15 +0330] "GET /x.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:12 +0330] "GET /old-index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:13 +0330] "GET /FoxWSO.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:17 +0330] "GET /403.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:20 +0330] "GET /mini.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:22 +0330] "GET /imagesvuln.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:25 +0330] "GET /wikindex.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:26 +0330] "GET /m.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:33 +0330] "GET /wp-wso.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:36 +0330] "GET /minimo.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:39 +0330] "GET /xleet.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:41 +0330] "GET /V3.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:46 +0330] "GET /404.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:48 +0330] "GET /up.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:50 +0330] "GET /www.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:51 +0330] "GET /100.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:02 +0330] "GET /f.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:06 +0330] "GET /o.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:07 +0330] "GET /new.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:08 +0330] "GET /sindex.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:10 +0330] "GET /wi.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:13 +0330] "GET /root.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:16 +0330] "GET /nee.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:17 +0330] "GET /v.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:18 +0330] "GET /z.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:20 +0330] "GET /g.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:22 +0330] "GET /c99.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:28 +0330] "GET /ws.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:30 +0330] "GET /2.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:33 +0330] "GET /7yn.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:33 +0330] "GET /haxor.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:34 +0330] "GET /13.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:35 +0330] "GET /e.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:36 +0330] "GET /r.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:39 +0330] "GET /y.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:23 +0330] "GET /edit-form.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:27 +0330] "GET /0byte.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:29 +0330] "GET /xx.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:30 +0330] "GET /new-index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:31 +0330] "GET /wp.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:34 +0330] "GET /qindex.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:36 +0330] "GET /priv8.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:44 +0330] "GET /V5.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:08:55 +0330] "GET /777.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:00 +0330] "GET /defau1t.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:04 +0330] "GET /xox.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:10 +0330] "GET /baindex.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:12 +0330] "GET /mar.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:23 +0330] "GET /w.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:30 +0330] "GET /lol.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:32 +0330] "GET /87.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:37 +0330] "GET /t.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:40 +0330] "GET /u.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:41 +0330] "GET /i.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:45 +0330] "GET /p.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:46 +0330] "GET /q.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:46 +0330] "GET /s.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:49 +0330] "GET /h.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:51 +0330] "GET /j.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:52 +0330] "GET /k.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:53 +0330] "GET /l.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:57 +0330] "GET /kindex.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:01 +0330] "GET /bb.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:02 +0330] "GET /lf.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:03 +0330] "GET /WSO.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:08 +0330] "GET /hello.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:12 +0330] "GET /mrjn.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:16 +0330] "GET /kn.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:17 +0330] "GET /3301.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:48 +0330] "GET /d.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:54 +0330] "GET /n.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:55 +0330] "GET /xindex.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:09:58 +0330] "GET /FoxWSOv1.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:00 +0330] "GET /alf.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:09 +0330] "GET /ok.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:10 +0330] "GET /if.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:11 +0330] "GET /kk.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:19 +0330] "GET /leaf.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:23 +0330] "GET /wp-ad.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:24 +0330] "GET /send.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:26 +0330] "GET /.wp-cache.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:29 +0330] "GET /sendmail.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:30 +0330] "GET /rahma.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:34 +0330] "GET /alfa123.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:36 +0330] "GET /upload.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:37 +0330] "GET /bypass.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:19 +0330] "GET /alex.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:21 +0330] "GET /mailer.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:21 +0330] "GET /anone.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:22 +0330] "GET /wp-configer.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:25 +0330] "GET /3.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:31 +0330] "GET /nasgor.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:33 +0330] "GET /wp-confirm.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:38 +0330] "GET /wp-one.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:44 +0330] "GET /blog.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:48 +0330] "GET /0.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:52 +0330] "GET /vuln.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:56 +0330] "GET /wp-admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:57 +0330] "GET /cms.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:00 +0330] "GET /wp-uploads.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:02 +0330] "GET /41.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:05 +0330] "GET /MARIJUANA.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:11 +0330] "GET /.fk.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:39 +0330] "GET /alexus.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:41 +0330] "GET /wso1337.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:43 +0330] "GET /1337.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:46 +0330] "GET /it.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:47 +0330] "GET /kiss.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:49 +0330] "GET /wp2.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:51 +0330] "GET /owl.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:10:54 +0330] "GET /ohayo.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:01 +0330] "GET /Gel.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:04 +0330] "GET /4price.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:10 +0330] "GET /marijuana.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:14 +0330] "GET /alexuse.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:15 +0330] "GET /content.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:17 +0330] "GET /leafmailer2.8.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:19 +0330] "GET /olu.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:19 +0330] "GET /alexusmailer%202.0.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:21 +0330] "GET /rss.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:25 +0330] "GET /alexus-mailer.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:29 +0330] "GET /wso2.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:36 +0330] "GET /wp-info.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:37 +0330] "GET /xl.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:44 +0330] "GET /leafmailer.php HTTP/1.1" 403 6886 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:46 +0330] "GET /ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:53 +0330] "GET /wp-admin/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:56 +0330] "GET /wp-includes/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:59 +0330] "GET /css/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:00 +0330] "GET /files/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:01 +0330] "GET /images/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:02 +0330] "GET /ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:04 +0330] "GET /wp-admin/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:05 +0330] "GET /wp-content/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:15 +0330] "GET /Sendemail.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:26 +0330] "GET /wp-file.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:32 +0330] "GET /wso1.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:33 +0330] "GET /olux.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:39 +0330] "GET /wp-confiig.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:40 +0330] "GET /file-manager.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:42 +0330] "GET /uploader.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:48 +0330] "GET /.well-known/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:50 +0330] "GET /tmp_images/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:55 +0330] "GET /wp-content/alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:11:57 +0330] "GET /alfacgiapi/perl.alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:07 +0330] "GET /wp-includes/ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:10 +0330] "GET /about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:14 +0330] "GET /wp-content/plugins/cekidot/alf.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:21 +0330] "GET /snd.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:27 +0330] "GET /wp-content/plugins/ubh/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:08 +0330] "GET /date.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:11 +0330] "GET /alfaindex.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:12 +0330] "GET /.alf.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:15 +0330] "GET /wp-content/fw.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:17 +0330] "GET /wp-content/alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:22 +0330] "GET /wp-class.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:23 +0330] "GET /small.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:24 +0330] "GET /wp-content/plugins/upspy/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:33 +0330] "GET /wp-content/plugins/three-column-screen-layout/db.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:34 +0330] "GET /wp-content/plugins/xichang/x.php?xi HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:35 +0330] "GET /wp-content/plugins/html404/index.html HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:37 +0330] "GET /wp-content/plugins/wp-db-ajax-made/wp-ajax.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:42 +0330] "GET /wp-includes/css/modules.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:44 +0330] "GET /wp-content/plugins/css-ready-sel/file.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:46 +0330] "GET /wp-content/plugins/css-ready/file.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:29 +0330] "GET /wp-content/plugins/vwcleanerplugin/bump.php?cache HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:30 +0330] "GET /wp-content/themes/gaukingo/db.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:40 +0330] "GET /Marvins.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:43 +0330] "GET /indoxploit.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:53 +0330] "GET /wp-content/plugins/html404/cry.php.pjpeg HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:55 +0330] "GET /wp-content/plugins/html404/wso25.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:56 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:57 +0330] "GET /libraries/joomla/css.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:58 +0330] "GET /libraries/joomla/jmails.php?u HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:01 +0330] "GET /images/vuln.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:03 +0330] "GET /rxr.php?rxr HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:07 +0330] "GET /wp-content/themes/fitnessbase/404.php?ok HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:10 +0330] "GET /wp-add-admin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:14 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:17 +0330] "GET /administrator/templates/bluestork/error.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:48 +0330] "GET /wp-content/think.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:50 +0330] "GET /wp-content/plugins/html404/xccc.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:53 +0330] "GET /wp-content/plugins/real/v.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:12:59 +0330] "GET /libraries/joomla/jmail.php?u HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:03 +0330] "GET /tmp/vuln.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:04 +0330] "GET /modules/modules/modules.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:07 +0330] "GET /error.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:11 +0330] "GET /RxR.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:16 +0330] "GET /components/com_b2jcontact/izoc.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:24 +0330] "GET /administrator/templates/isis/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:29 +0330] "GET /templates/beez/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:30 +0330] "GET /templates/ja_purity/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:32 +0330] "GET /templates/rhuk_milkyway/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:34 +0330] "GET /templates/+theme+/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:35 +0330] "GET /templates/+theme+/error.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:18 +0330] "GET /administrator/templates/hathor/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:22 +0330] "GET /administrator/templates/hathor/error.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:27 +0330] "GET /administrator/templates/isis/error.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:37 +0330] "GET /templates/beez3/error.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:39 +0330] "GET /templates/beez5/error.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:41 +0330] "GET /templates/beez_20/index.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:44 +0330] "GET /templates/beez_20/error.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:47 +0330] "GET /templates/atomic/index.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:50 +0330] "GET /wp-admin/network/wp-footer.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:50 +0330] "GET /wp-content/vuln.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:51 +0330] "GET /upel.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:53 +0330] "GET /wp-content/uploads/+year+/+month+/ HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:56 +0330] "GET /license.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:56 +0330] "GET /wp-content/plugins/ppus/up.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:57 +0330] "GET /098.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:59 +0330] "GET /wp-content/plugins/theme-configurator/mini.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:02 +0330] "GET /wp-content/plugins/widget-logic/mini.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:08 +0330] "GET /1975.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:10 +0330] "GET /1975.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:10 +0330] "GET /radio.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:11 +0330] "GET /wp-includes/wp-class.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:15 +0330] "GET /wp-content/radio.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:16 +0330] "GET /wp-includes/radio.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:18 +0330] "GET /fx.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:19 +0330] "GET /wp-admin/images/atomlib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:21 +0330] "GET /jindex.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:24 +0330] "GET /wp-content/about.php HTTP/1.1" 403 6886 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:27 +0330] "GET /wp-includes/991176.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:30 +0330] "GET /fox.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:31 +0330] "GET /wp-admin/x.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:37 +0330] "GET /4.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:36 +0330] "GET /templates/beez3/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:38 +0330] "GET /templates/beez5/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:44 +0330] "GET /templates/protostar/index.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:45 +0330] "GET /templates/protostar/error.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:48 +0330] "GET /templates/atomic/error.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:53 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:13:58 +0330] "GET /new_license.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:04 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:14 +0330] "GET /xleet-shell.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:20 +0330] "GET /gel4y.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:26 +0330] "GET /sh.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:28 +0330] "GET /wp-admin/maint/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:32 +0330] "GET /fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:33 +0330] "GET /server.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:36 +0330] "GET /wp-includes/fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:39 +0330] "GET /images/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:43 +0330] "GET /wp-load.php HTTP/1.1" 403 6886 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:45 +0330] "GET /wp-admin/fw.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:49 +0330] "GET /mari.php HTTP/1.1" 403 6886 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:52 +0330] "GET /swm.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:58 +0330] "GET /wp-content/wso.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:01 +0330] "GET /w3llstore.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:02 +0330] "GET /wp-content/fx.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:05 +0330] "GET /wp-admin/alfa.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:10 +0330] "GET /style.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:13 +0330] "GET /s_e.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:15 +0330] "GET /beence.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:16 +0330] "GET /wp-signin.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:20 +0330] "GET /export.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:22 +0330] "GET /legion.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:24 +0330] "GET /shells.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:28 +0330] "GET /wp-includes/wp-atom.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:39 +0330] "GET /5.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:42 +0330] "GET /xmlrpc.php HTTP/1.1" 403 6886 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:44 +0330] "GET /wp-login.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:53 +0330] "GET /wp-admin/radio.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:55 +0330] "GET /wp-includes/about.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:14:59 +0330] "GET /wp-admin/wso.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:04 +0330] "GET /wp-content/x.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:08 +0330] "GET /gank.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:14 +0330] "GET /s_ne.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:18 +0330] "GET /moduless.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:22 +0330] "GET /system_log.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:36 +0330] "GET /wp-content/plugins/backup_index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:37 +0330] "GET /wp-includes/css/wp-config.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:42 +0330] "GET /wp-content/uploads/wp-stream.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:43 +0330] "GET /wp-beckup.php HTTP/1.1" 403 6886 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:49 +0330] "GET /wp-admin/style.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:32 +0330] "GET /wp-content/plugins/ubh/up.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:33 +0330] "GET /wp-content/mu-plugins/db-safe-mode.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:34 +0330] "GET /wp-content/db-cache.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:38 +0330] "GET /wp-content/themes/config.bak.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:40 +0330] "GET /wp-includes/images/css.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:42 +0330] "GET /wp-includes/css/css.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:45 +0330] "GET /wp-blog-post.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:46 +0330] "GET /wp-content/uploads/wp-blockdown.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:46 +0330] "GET /wp-admin/includes/class-wp-media-list-data.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:49 +0330] "GET /6.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:57 +0330] "GET /10.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:01 +0330] "GET /wp-includes/wp_class_datlib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:03 +0330] "GET /wp-includes/pomo/wp_class_datalib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:05 +0330] "GET /marijuana.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:07 +0330] "GET /1xleet.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:09 +0330] "GET /wp-content/shell.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:50 +0330] "GET /7.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:52 +0330] "GET /8.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:15:54 +0330] "GET /9.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:00 +0330] "GET /wp_class_datalib.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:04 +0330] "GET /01.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:12 +0330] "GET /wp-admin/shell.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:13 +0330] "GET /wp-admin/wp.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:15 +0330] "GET /4index.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:16 +0330] "GET /5index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:18 +0330] "GET /7index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:19 +0330] "GET /8index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:26 +0330] "GET /alfashell.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:34 +0330] "GET /goods.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:37 +0330] "GET /lab.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:40 +0330] "GET /leaf_php.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:46 +0330] "GET /mailer1.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:11 +0330] "GET /wp-content/fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:17 +0330] "GET /6index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:20 +0330] "GET /9index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:21 +0330] "GET /Leaf.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:23 +0330] "GET /Uploader.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:24 +0330] "GET /wp-includes/wp-red.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:24 +0330] "GET /.well-known/radio.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:27 +0330] "GET /am.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:27 +0330] "GET /blog/fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:28 +0330] "GET /contacts.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:29 +0330] "GET /demo328/fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:32 +0330] "GET /gif.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:36 +0330] "GET /images/sym.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:38 +0330] "GET /leaf_mailer.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:42 +0330] "GET /libraries/joomla/jmail.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:42 +0330] "GET /libraries/joomla/jmails.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:46 +0330] "GET /ms.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:48 +0330] "GET /rxr.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:53 +0330] "GET /unix.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:56 +0330] "GET /uploads/up.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:57 +0330] "GET /wp-admin/css/fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:00 +0330] "GET /wp-admin/includes/fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:01 +0330] "GET /wp-admin/maint/fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:05 +0330] "GET /wp-admin/setup-config.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:05 +0330] "GET /wp-content/plugins/vwcleanerplugin/bump.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:07 +0330] "GET /wp-content/plugins/xichang/x.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:20 +0330] "GET /wp-content/wp.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:21 +0330] "GET /wp-mna.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:23 +0330] "GET /wpx.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:28 +0330] "GET /xhell.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:29 +0330] "GET /xmrlpc.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:36 +0330] "GET /wp-content/plugins/vwcleanerplugin/bump.php?cache HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:48 +0330] "GET /srx.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:50 +0330] "GET /tuco.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:16:57 +0330] "GET /wp-admin/css/colors/coffee/fw.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:10 +0330] "GET /wp-content/plugins/zedd/1.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:16 +0330] "GET /wp-content/up.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:23 +0330] "GET /uploads/upload.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:27 +0330] "GET /images/c99.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:31 +0330] "GET /xz.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:33 +0330] "GET /yuuki.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:34 +0330] "GET /wp-content/plugins/upspy/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:36 +0330] "GET /wp-content/plugins/ubh/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:41 +0330] "GET /wp-content/plugins/three-column-screen-layout/db.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:42 +0330] "GET /wp-content/plugins/xichang/x.php?xi HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:44 +0330] "GET /wp-content/plugins/html404/index.html HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:47 +0330] "GET /wp-content/plugins/wp-db-ajax-made/wp-ajax.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:51 +0330] "GET /Marvins.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:38 +0330] "GET /wp-content/themes/gaukingo/db.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:48 +0330] "GET /wp-admin/shapes.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:58 +0330] "GET /indoxploit.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:00 +0330] "GET /wp-content/plugins/css-ready-sel/file.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:03 +0330] "GET /wp-content/think.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:08 +0330] "GET /wp-content/plugins/upspy/sllolx.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:09 +0330] "GET /database.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:11 +0330] "GET /shell20211028.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:13 +0330] "GET /wp-blog.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:16 +0330] "GET /wp-includes/wp-class.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:17 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:53 +0330] "GET /wp-includes/css/modules.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:56 +0330] "GET /olux.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:17:59 +0330] "GET /wso.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:01 +0330] "GET /wp-content/plugins/css-ready/file.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:04 +0330] "GET /wp-content/plugins/upspy/con.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:07 +0330] "GET /wp-content/plugins/upspy/up.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:10 +0330] "GET /wp-includes/js/tinymce/plugins/compat3x/css/index.php HTTP/1.1" 403 6888 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 131.163.89.4 - - [04/Nov/2025:17:18:14 +0330] "GET /repeater.php HTTP/1.1" 403 6889 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 74.176.208.147 - - [04/Nov/2025:18:25:51 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 66.249.66.13 - - [04/Nov/2025:19:01:27 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 5.255.231.104 - - [04/Nov/2025:19:56:15 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 185.241.208.62 - - [04/Nov/2025:19:58:58 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:19:58:58 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 185.241.208.62 - - [04/Nov/2025:19:58:58 +0330] "POST /wp-plain.php HTTP/1.1" 404 101447 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 87.250.224.94 - - [04/Nov/2025:20:02:15 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 43.166.136.202 - - [04/Nov/2025:20:02:50 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 213.180.203.211 - - [04/Nov/2025:20:04:15 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 213.180.203.147 - - [04/Nov/2025:20:06:15 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 95.108.213.197 - - [04/Nov/2025:20:08:19 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 5.255.231.55 - - [04/Nov/2025:19:58:15 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 185.241.208.62 - - [04/Nov/2025:19:58:58 +0330] "GET / HTTP/1.1" 403 17364 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:19:58:58 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:19:58:59 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:19:59:04 +0330] "GET /jyuvocch.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.32.178.104 - - [04/Nov/2025:19:59:22 +0330] "GET /.env HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 95.108.213.205 - - [04/Nov/2025:20:00:15 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 95.108.213.235 - - [04/Nov/2025:20:12:22 +0330] "GET /robots.txt HTTP/1.1" 301 0 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" 31.214.174.196 - - [04/Nov/2025:20:37:15 +0330] "GET /.well-known/pki-validation/dropdown.php HTTP/1.1" 404 796 "-" "get_local:DCV" 64.226.121.166 - - [04/Nov/2025:20:34:04 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 70.166.167.38 - - [04/Nov/2025:20:45:30 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 70.166.167.38 - - [04/Nov/2025:20:45:51 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 129.100.255.80 - - [04/Nov/2025:20:50:35 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36" 85.174.207.48 - - [04/Nov/2025:20:52:24 +0330] "GET /wp-content/plugins/king-addons/freemius/assets/css/customizer.css HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36" 70.166.167.38 - - [04/Nov/2025:20:45:43 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 70.166.167.38 - - [04/Nov/2025:20:45:58 +0330] "GET / HTTP/1.0" 301 0 "http://optimyar.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0" 72.139.192.216 - - [04/Nov/2025:20:47:54 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_6_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/141.0.7390.96 Mobile/15E148 Safari/604.1" 188.134.62.171 - - [04/Nov/2025:21:02:11 +0330] "GET /wp-content/plugins/post-smtp/assets/js/postman-suggest.js HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko)" 18.224.192.118 - - [04/Nov/2025:21:11:26 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 170.106.180.153 - - [04/Nov/2025:21:03:45 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 193.36.224.76 - - [04/Nov/2025:21:21:04 +0330] "GET /ss.php?f_c=1 HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 104.234.19.44 - - [04/Nov/2025:21:21:10 +0330] "GET /ss.php?f_c=1 HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.62 - - [04/Nov/2025:22:01:34 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:22:01:35 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:22:01:34 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 185.241.208.62 - - [04/Nov/2025:22:01:34 +0330] "POST /wp-plain.php HTTP/1.1" 404 101447 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:22:01:34 +0330] "GET / HTTP/1.1" 403 17364 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:22:01:34 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.62 - - [04/Nov/2025:22:01:39 +0330] "GET /yeyaakbx.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 185.241.208.77 - - [04/Nov/2025:22:10:53 +0330] "GET /style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:10:59 +0330] "GET /wp-content/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:09 +0330] "GET /wp-admin/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:32 +0330] "GET /file.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:36 +0330] "GET /flower.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:41 +0330] "GET /gifclass.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:50 +0330] "GET /class-t.api.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:55 +0330] "GET /blurbs.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:59 +0330] "GET /akcc.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:37 +0330] "GET /wp-admin/zwso.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:46 +0330] "GET /wp-content/plugins/hellopress/wp_mna.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:56 +0330] "GET /shlo.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:01 +0330] "GET /133.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:05 +0330] "GET /ahax.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:16 +0330] "GET /witmm.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:35 +0330] "GET /wp-editor.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:04 +0330] "GET /wp-content/themes/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:18 +0330] "GET /wp-includes/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:24 +0330] "GET /chosen.php?p= HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:11:46 +0330] "GET /bless.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:04 +0330] "GET /abcd.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:08 +0330] "GET /aku.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:13 +0330] "GET /cord.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:18 +0330] "GET /dex.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:22 +0330] "GET /wp-admin/admin-ajax.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:26 +0330] "GET /zoo.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:31 +0330] "GET //zwso.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:12:51 +0330] "GET /bolt.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:10 +0330] "GET /wpssl.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:20 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:30 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 200 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:30 +0330] "GET /wp-content/index.php HTTP/1.1" 200 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [04/Nov/2025:22:13:30 +0330] "GET /files.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 20.169.255.112 - - [04/Nov/2025:23:09:25 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 74.176.49.2 - - [04/Nov/2025:23:27:13 +0330] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 119.18.146.244 - - [05/Nov/2025:00:19:16 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 78.29.51.51 - - [05/Nov/2025:00:52:36 +0330] "GET /wp-content/plugins/WordPressCore/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 81.88.52.239 - - [05/Nov/2025:00:58:51 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 5.181.171.105 - - [05/Nov/2025:01:26:33 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10" 5.181.171.105 - - [05/Nov/2025:01:26:41 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10" 5.181.171.105 - - [05/Nov/2025:01:26:47 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10" 185.2.5.31 - - [05/Nov/2025:01:57:17 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 2.58.56.14 - - [05/Nov/2025:02:06:43 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 2.58.56.14 - - [05/Nov/2025:02:06:43 +0330] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 2.58.56.14 - - [05/Nov/2025:02:06:42 +0330] "GET / HTTP/1.1" 403 17364 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 2.58.56.14 - - [05/Nov/2025:02:06:43 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 2.58.56.14 - - [05/Nov/2025:02:06:43 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17364 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 2.58.56.14 - - [05/Nov/2025:02:06:42 +0330] "POST /wp-plain.php HTTP/1.1" 404 101902 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 2.58.56.14 - - [05/Nov/2025:02:06:47 +0330] "GET /sujzhyfv.php?Fox=d3wL7 HTTP/1.1" 301 0 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 117.7.84.2 - - [05/Nov/2025:02:23:34 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 149.88.19.85 - - [05/Nov/2025:02:24:53 +0330] "GET /id/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:56 +0330] "GET /www/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:00 +0330] "GET /web/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:06 +0330] "GET /uploads/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:09 +0330] "GET /upload/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:13 +0330] "GET /admin/uploads/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:16 +0330] "GET /Admin/uploads/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:20 +0330] "GET /admin/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:23 +0330] "GET /images/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:24 +0330] "GET /assets/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:28 +0330] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:31 +0330] "GET /upload/image/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:35 +0330] "GET /assets/images/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:38 +0330] "GET /Public/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:42 +0330] "GET /vendor/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:45 +0330] "GET /local/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:52 +0330] "GET /modules/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:56 +0330] "GET /Site/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:25:59 +0330] "GET /system/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:04 +0330] "GET /template/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:08 +0330] "GET /shop/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:12 +0330] "GET /files/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:16 +0330] "GET /admin/editor/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:20 +0330] "GET /include/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:24 +0330] "GET /Assets/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:27 +0330] "GET /images/stories/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:31 +0330] "GET /plugins/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:35 +0330] "GET /php/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:40 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:40 +0330] "GET /wp-content/themes/twentytwenty/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:40 +0330] "GET /wp-content/cache/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:44 +0330] "GET /wp-admin/maint/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:44 +0330] "GET /wp-content/plugins/akismet/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:44 +0330] "GET /wp-includes/assets/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:44 +0330] "GET /wp-includes/block-patterns/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:44 +0330] "GET /wp-includes/block-supports/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:44 +0330] "GET /wp-includes/html-api/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:45 +0330] "GET /wp-includes/js/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:45 +0330] "GET /wp-includes/php-compat/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:45 +0330] "GET /wp-includes/PHPMailer/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:45 +0330] "GET /wp-includes/pomo/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:45 +0330] "GET /wp-includes/random_compat/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:49 +0330] "GET /wp-includes/rest-api/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:49 +0330] "GET /wp-includes/sitemaps/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:49 +0330] "GET /wp-includes/sodium_compat/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:49 +0330] "GET /wp-includes/style-engine/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:49 +0330] "GET /wp-includes/theme-compat/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:50 +0330] "GET /wp-includes/widgets/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:50 +0330] "GET /wp-admin/css/colors/ectoplasm/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:50 +0330] "GET /wp-admin/css/colors/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:50 +0330] "GET /admin/images/slider/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:54 +0330] "GET /admin/fckeditor/editor/filemanager/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:26:57 +0330] "GET /sites/default/files/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:01 +0330] "GET /admin/controller/extension/extension/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:07 +0330] "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:11 +0330] "GET /components/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:14 +0330] "GET /admin/uploads/images/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:18 +0330] "GET /wp-content/plugins/classic-editor/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:21 +0330] "GET /wp-content/fonts/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:25 +0330] "GET /wp-content/plugins/contact-form-7/admin/js/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:29 +0330] "GET /wp-content/plugins/contact-form-7/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:33 +0330] "GET /wordpress/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:36 +0330] "GET /wp-admin/images/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:36 +0330] "GET /wp-content/plugins/wordpress-seo/js/dist/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:36 +0330] "GET /wp-content/plugins/wordpress-seo/ HTTP/1.1" 500 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:37 +0330] "GET /js/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:37 +0330] "GET /wp-content/plugins/woocommerce/assets/js/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:41 +0330] "GET /wp-content/plugins/woocommerce/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:44 +0330] "GET /wp-admin/meta/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:28:07 +0330] "GET /wp-content/ HTTP/1.1" 500 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:28:08 +0330] "GET /wp-content/plugins/ HTTP/1.1" 500 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:28:08 +0330] "GET /wp-content/themes/ HTTP/1.1" 500 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:28:08 +0330] "GET /wp-admin/includes/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:28:08 +0330] "GET /wp-admin/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:28:16 +0330] "GET /wp-content/upgrade/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:21 +0330] "GET /wp-content/uploads/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:21 +0330] "GET /wp-includes/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:21 +0330] "GET /wp-includes/css/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:22 +0330] "GET /wp-includes/ID3/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:22 +0330] "GET /wp-includes/IXR/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:22 +0330] "GET /wp-includes/Requests/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:22 +0330] "GET /wp-includes/SimplePie/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:22 +0330] "GET /wp-includes/Text/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:22 +0330] "GET /wp-content/mu-plugins-old/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:26 +0330] "GET /wp-content/themes/classic/inc/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:30 +0330] "GET /wp-content/plugins/ninja-forms/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:34 +0330] "GET /wp-content/mu-plugins/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:38 +0330] "GET /wp-includes/Text/Diff/Renderer/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:38 +0330] "GET /wp-includes/blocks/ HTTP/1.1" 500 2 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:38 +0330] "GET /wp-includes/certificates/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:38 +0330] "GET /wp-includes/customize/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:39 +0330] "GET /wp-includes/fonts/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:39 +0330] "GET /wp-includes/images/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:39 +0330] "GET /.well-known/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:39 +0330] "GET /ALFA_DATA/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:43 +0330] "GET /.well-knownold/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:47 +0330] "GET /.well-known/acme-challenge/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:47 +0330] "GET /cgi-bin/ HTTP/1.1" 403 787 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:24:47 +0330] "GET /index/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:50 +0330] "GET /wp-admin/network/ HTTP/1.1" 301 0 "-" "-" 149.88.19.85 - - [05/Nov/2025:02:27:57 +0330] "GET /wp-admin/user/ HTTP/1.1" 301 0 "-" "-" 74.176.49.2 - - [05/Nov/2025:02:39:05 +0330] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 223.204.8.58 - - [05/Nov/2025:02:39:35 +0330] "GET /wp-json/wp/v2/posts HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 136.144.19.164 - - [05/Nov/2025:03:21:25 +0330] "GET /postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 136.144.19.180 - - [05/Nov/2025:03:21:32 +0330] "GET /wp-content/postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 136.144.19.180 - - [05/Nov/2025:03:21:37 +0330] "GET /wp-admin/postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 199.244.88.224 - - [05/Nov/2025:03:23:35 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 45.149.173.227 - - [05/Nov/2025:04:57:04 +0330] "GET / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 38.146.28.139 - - [05/Nov/2025:06:04:11 +0330] "GET /postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 38.146.28.139 - - [05/Nov/2025:06:04:17 +0330] "GET /wp-content/postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 38.146.28.139 - - [05/Nov/2025:06:04:21 +0330] "GET /wp-admin/postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 45.153.160.187 - - [05/Nov/2025:06:10:37 +0330] "GET /dup-installer/main.installer.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 38.146.28.139 - - [05/Nov/2025:06:52:14 +0330] "GET /postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 38.146.28.139 - - [05/Nov/2025:06:52:24 +0330] "GET /wp-content/postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 38.146.28.139 - - [05/Nov/2025:06:52:30 +0330] "GET /wp-admin/postnews.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 87.117.185.237 - - [05/Nov/2025:07:32:02 +0330] "GET /wp-content/plugins/king-addons/freemius/assets/css/customizer.css HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.6 Safari/605.1.15" 5.35.130.22 - - [05/Nov/2025:07:32:27 +0330] "GET /wp-content/plugins/king-addons/freemius/assets/css/customizer.css HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 14.215.163.132 - - [05/Nov/2025:07:24:18 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 88.147.178.152 - - [05/Nov/2025:07:42:15 +0330] "GET /wp-content/plugins/post-smtp/assets/js/postman-suggest.js HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" 74.176.49.2 - - [05/Nov/2025:08:10:21 +0330] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36" 185.2.4.131 - - [05/Nov/2025:09:02:14 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0" 109.123.251.106 - - [05/Nov/2025:09:28:38 +0330] "GET /wp-admin/css/ HTTP/1.1" 403 787 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 5.160.50.46 - - [05/Nov/2025:09:44:15 +0330] "GET /wp-content/uploads/2020/12/logo2.png HTTP/1.1" 200 4490 "https://optimyar.com/" "Mozilla/5.0 (Windows NT 6.1; rv:109.0) Gecko/20100101 Firefox/115.0" 194.165.16.8 - - [05/Nov/2025:10:04:39 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0" 119.249.100.170 - - [05/Nov/2025:10:10:25 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 220.181.51.90 - - [05/Nov/2025:10:10:20 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 43.157.38.228 - - [05/Nov/2025:10:29:21 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 43.166.244.192 - - [05/Nov/2025:11:28:31 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 37.110.134.107 - - [05/Nov/2025:11:17:39 +0330] "GET /wp-content/plugins/WordPressCore/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" 46.228.119.63 - - [05/Nov/2025:11:18:24 +0330] "GET /wp-content/plugins/WordPressCore/include.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 209.172.2.50 - - [05/Nov/2025:12:17:38 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:127.0) Gecko/20100101 Firefox/127.0" 66.249.66.201 - - [05/Nov/2025:12:19:37 +0330] "GET /wp-content/uploads/2022/05/photo_2022-05-08_15-30-18.jpg HTTP/1.1" 304 0 "-" "Googlebot-Image/1.0" 31.214.174.196 - - [05/Nov/2025:12:15:10 +0330] "POST /wp-cron.php?doing_wp_cron=1762332310.6862130165100097656250 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 4.224.244.18 - - [05/Nov/2025:12:15:08 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.5672.93 Safari/537.36" 31.214.174.196 - - [05/Nov/2025:12:17:41 +0330] "POST /wp-cron.php?doing_wp_cron=1762332461.3358778953552246093750 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 66.249.66.11 - - [05/Nov/2025:12:19:34 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 89.46.110.103 - - [05/Nov/2025:12:23:40 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Edg/126.0.0.0" 103.75.187.239 - - [05/Nov/2025:12:29:31 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.5615.138 Safari/537.36" 31.214.174.196 - - [05/Nov/2025:12:35:52 +0330] "POST /wp-cron.php?doing_wp_cron=1762333552.1259629726409912109375 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 68.183.58.166 - - [05/Nov/2025:12:35:49 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 31.214.174.196 - - [05/Nov/2025:12:29:34 +0330] "POST /wp-cron.php?doing_wp_cron=1762333174.1953220367431640625000 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 91.229.236.31 - - [05/Nov/2025:12:32:35 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5) AppleWebKit/618.3.5 (KHTML, like Gecko) Version/17.4 Safari/618.3.5" 119.148.35.66 - - [05/Nov/2025:12:39:20 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15" 31.214.174.196 - - [05/Nov/2025:12:39:22 +0330] "POST /wp-cron.php?doing_wp_cron=1762333762.6233689785003662109375 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 157.245.6.207 - - [05/Nov/2025:12:46:09 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.96 Safari/537.36" 31.214.174.196 - - [05/Nov/2025:12:49:40 +0330] "POST /wp-cron.php?doing_wp_cron=1762334380.5933690071105957031250 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 31.214.174.196 - - [05/Nov/2025:12:53:15 +0330] "POST /wp-cron.php?doing_wp_cron=1762334595.7542879581451416015625 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 89.46.106.152 - - [05/Nov/2025:12:53:13 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15" 132.145.155.93 - - [05/Nov/2025:12:49:37 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.3) AppleWebKit/614.31.14 (KHTML, like Gecko) Version/17.0.96 Safari/614.31.14" 103.6.198.100 - - [05/Nov/2025:12:56:48 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.134 Safari/537.36" 31.214.174.196 - - [05/Nov/2025:13:03:53 +0330] "POST /wp-cron.php?doing_wp_cron=1762335233.7709479331970214843750 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 31.214.174.196 - - [05/Nov/2025:13:00:25 +0330] "POST /wp-cron.php?doing_wp_cron=1762335025.9228639602661132812500 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 89.42.218.162 - - [05/Nov/2025:13:00:23 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0" 91.229.236.31 - - [05/Nov/2025:13:03:51 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:129.0) Gecko/20100101 Firefox/129.0" 135.125.183.119 - - [05/Nov/2025:13:10:52 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3.1 Safari/605.1.15" 182.44.2.148 - - [05/Nov/2025:13:14:38 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 74.176.49.2 - - [05/Nov/2025:13:17:46 +0330] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 152.206.75.226 - - [05/Nov/2025:13:17:55 +0330] "POST /xmlrpc.php HTTP/1.1" 405 89 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.96 Safari/537.36" 31.214.174.196 - - [05/Nov/2025:13:24:55 +0330] "POST /wp-cron.php?doing_wp_cron=1762336495.7807419300079345703125 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 81.88.53.133 - - [05/Nov/2025:13:24:53 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.102 Safari/537.36" 31.214.174.196 - - [05/Nov/2025:13:28:31 +0330] "POST /wp-cron.php?doing_wp_cron=1762336711.7042140960693359375000 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 188.165.71.78 - - [05/Nov/2025:13:28:28 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15" 74.176.49.2 - - [05/Nov/2025:13:17:46 +0330] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 74.176.49.2 - - [05/Nov/2025:13:17:46 +0330] "GET / HTTP/1.1" 403 17362 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 74.176.49.2 - - [05/Nov/2025:13:17:47 +0330] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 17362 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 31.214.174.196 - - [05/Nov/2025:13:17:49 +0330] "POST /wp-cron.php?doing_wp_cron=1762336069.2482900619506835937500 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 74.176.49.2 - - [05/Nov/2025:13:17:46 +0330] "POST /wp-plain.php HTTP/1.1" 404 101902 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 209.38.230.167 - - [05/Nov/2025:13:21:23 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.134 Safari/537.36" 193.112.75.42 - - [05/Nov/2025:13:32:08 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.134 Safari/537.36" 134.122.6.46 - - [05/Nov/2025:13:35:48 +0330] "POST /xmlrpc.php HTTP/1.1" 405 89 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.171 Safari/537.36 Edg/115.0.1901.203" 31.214.174.196 - - [05/Nov/2025:13:39:36 +0330] "POST /wp-cron.php?doing_wp_cron=1762337376.0542800426483154296875 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 70.40.255.83 - - [05/Nov/2025:13:39:33 +0330] "POST /xmlrpc.php HTTP/1.1" 503 19461 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0.1) Gecko/20100101 Firefox/125.0.1" 185.241.208.77 - - [05/Nov/2025:13:42:32 +0330] "GET /style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:42:38 +0330] "GET /wp-content/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:42:57 +0330] "GET /wp-includes/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:08 +0330] "GET /file.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:13 +0330] "GET /flower.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:17 +0330] "GET /gifclass.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:22 +0330] "GET /bless.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:26 +0330] "GET /class-t.api.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:34 +0330] "GET /akcc.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:39 +0330] "GET /abcd.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:43 +0330] "GET /aku.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:12 +0330] "GET /wp-admin/zwso.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:38 +0330] "GET /ahax.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:48 +0330] "GET /witmm.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:52 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:45:05 +0330] "GET /wp-editor.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.117.225.7 - - [05/Nov/2025:13:31:41 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "python-requests/2.31.0" 185.117.225.7 - - [05/Nov/2025:13:31:47 +0330] "GET / HTTP/1.1" 301 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36 BitSightBot/1.0" 185.241.208.77 - - [05/Nov/2025:13:42:43 +0330] "GET /wp-content/themes/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:42:48 +0330] "GET /wp-admin/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:01 +0330] "GET /chosen.php?p= HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 37.27.52.80 - - [05/Nov/2025:13:43:02 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.96 Safari/537.36 Edg/116.0.1938.62" 185.241.208.77 - - [05/Nov/2025:13:43:30 +0330] "GET /blurbs.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:47 +0330] "GET /cord.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:52 +0330] "GET /dex.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:56 +0330] "GET /wp-admin/admin-ajax.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:43:59 +0330] "GET /zoo.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:04 +0330] "GET //zwso.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:21 +0330] "GET /wp-content/plugins/hellopress/wp_mna.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:26 +0330] "GET /bolt.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:30 +0330] "GET /shlo.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:34 +0330] "GET /133.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:44:43 +0330] "GET /wpssl.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:45:00 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 500 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:45:00 +0330] "GET /wp-content/index.php HTTP/1.1" 500 20 "-" "Go-http-client/1.1" 185.241.208.77 - - [05/Nov/2025:13:45:00 +0330] "GET /files.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 165.84.218.233 - - [05/Nov/2025:13:46:42 +0330] "POST /xmlrpc.php HTTP/1.1" 405 89 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.3) AppleWebKit/614.31.14 (KHTML, like Gecko) Version/17.0.96 Safari/614.31.14" 165.22.5.123 - - [05/Nov/2025:13:50:21 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7596 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.96 Safari/537.36" 2.58.56.150 - - [05/Nov/2025:13:53:49 +0330] "GET /style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:53:58 +0330] "GET /wp-content/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 50.62.183.174 - - [05/Nov/2025:13:54:04 +0330] "POST /xmlrpc.php HTTP/1.1" 405 89 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 2.58.56.150 - - [05/Nov/2025:13:54:14 +0330] "GET /wp-admin/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:54:28 +0330] "GET /wp-includes/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:54:48 +0330] "GET /file.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:54:57 +0330] "GET /flower.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:55:14 +0330] "GET /bless.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:55:22 +0330] "GET /class-t.api.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:55:30 +0330] "GET /blurbs.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:55:49 +0330] "GET /abcd.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:55:57 +0330] "GET /aku.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:56:06 +0330] "GET /cord.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:56:14 +0330] "GET /dex.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:56:38 +0330] "GET //zwso.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:57:07 +0330] "GET /wp-content/plugins/hellopress/wp_mna.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:57:24 +0330] "GET /shlo.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:57:33 +0330] "GET /133.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:57:59 +0330] "GET /witmm.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:58:07 +0330] "GET /wp-admin/css/index.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:58:20 +0330] "GET /wp-content/plugins/index.php HTTP/1.1" 500 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:54:07 +0330] "GET /wp-content/themes/style.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:54:37 +0330] "GET /chosen.php?p= HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:55:05 +0330] "GET /gifclass.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:55:40 +0330] "GET /akcc.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:56:23 +0330] "GET /wp-admin/admin-ajax.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:56:29 +0330] "GET /zoo.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:56:52 +0330] "GET /wp-admin/zwso.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:57:15 +0330] "GET /bolt.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:57:40 +0330] "GET /ahax.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:57:50 +0330] "GET /wpssl.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:58:24 +0330] "GET /wp-content/index.php HTTP/1.1" 500 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:58:26 +0330] "GET /files.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 2.58.56.150 - - [05/Nov/2025:13:58:35 +0330] "GET /wp-editor.php HTTP/1.1" 301 20 "-" "Go-http-client/1.1" 51.68.236.73 - - [05/Nov/2025:14:00:10 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; MJ12bot/v2.0.4; http://mj12bot.com/)" 31.214.174.196 - - [05/Nov/2025:14:04:58 +0330] "POST /wp-cron.php?doing_wp_cron=1762338898.0566790103912353515625 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 113.192.8.160 - - [05/Nov/2025:14:04:55 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.134 Safari/537.36" 66.249.66.201 - - [05/Nov/2025:14:11:28 +0330] "GET /robots.txt HTTP/1.1" 301 20 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.201 - - [05/Nov/2025:14:11:31 +0330] "GET /wp-content/uploads/2020/12/logo2.png HTTP/1.1" 304 0 "-" "Googlebot-Image/1.0" 4.224.244.18 - - [05/Nov/2025:14:19:41 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 31.214.174.196 - - [05/Nov/2025:14:16:04 +0330] "POST /wp-cron.php?doing_wp_cron=1762339564.2862091064453125000000 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 67.205.42.10 - - [05/Nov/2025:14:16:01 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 200.58.127.65 - - [05/Nov/2025:14:23:24 +0330] "POST /xmlrpc.php HTTP/1.1" 405 89 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15" 31.214.174.196 - - [05/Nov/2025:14:27:05 +0330] "POST /wp-cron.php?doing_wp_cron=1762340225.1170680522918701171875 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 91.224.92.120 - - [05/Nov/2025:14:29:14 +0330] "GET /wp-login.php HTTP/1.1" 301 20 "https://wordpress.org/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Gecko/20100101 Firefox/118.0.2" 209.15.119.224 - - [05/Nov/2025:14:27:02 +0330] "POST /xmlrpc.php HTTP/1.1" 405 89 "http://optimyar.com" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 165.22.218.230 - - [05/Nov/2025:14:34:20 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0" 103.16.198.9 - - [05/Nov/2025:14:41:50 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7596 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:127.0) Gecko/20100101 Firefox/127.0" 31.214.174.196 - - [05/Nov/2025:14:45:32 +0330] "POST /wp-cron.php?doing_wp_cron=1762341332.9212770462036132812500 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 81.88.53.143 - - [05/Nov/2025:14:45:30 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0.1) Gecko/20100101 Firefox/125.0.1" 31.214.174.196 - - [05/Nov/2025:14:41:53 +0330] "POST /wp-cron.php?doing_wp_cron=1762341113.6497828960418701171875 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 31.214.174.196 - - [05/Nov/2025:14:52:56 +0330] "POST /wp-cron.php?doing_wp_cron=1762341776.5701949596405029296875 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 152.32.251.112 - - [05/Nov/2025:14:52:54 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:126.0) Gecko/20100101 Firefox/126.0" 31.214.174.196 - - [05/Nov/2025:14:56:36 +0330] "POST /wp-cron.php?doing_wp_cron=1762341996.0711259841918945312500 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 159.65.158.125 - - [05/Nov/2025:14:56:33 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.171 Safari/537.36 Edg/115.0.1901.203" 31.214.174.196 - - [05/Nov/2025:15:00:10 +0330] "POST /wp-cron.php?doing_wp_cron=1762342210.8982160091400146484375 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 65.60.5.206 - - [05/Nov/2025:15:03:49 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.171 Safari/537.36 Edg/115.0.1901.203" 198.244.233.124 - - [05/Nov/2025:15:07:31 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:126.0) Gecko/20100101 Firefox/126.0" 141.98.11.16 - - [05/Nov/2025:14:56:41 +0330] "GET /postnews.php HTTP/1.1" 403 6887 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 103.213.38.234 - - [05/Nov/2025:15:00:08 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0" 31.214.174.196 - - [05/Nov/2025:15:03:51 +0330] "POST /wp-cron.php?doing_wp_cron=1762342431.8867130279541015625000 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 31.214.174.196 - - [05/Nov/2025:15:07:33 +0330] "POST /wp-cron.php?doing_wp_cron=1762342653.5032939910888671875000 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 213.156.43.111 - - [05/Nov/2025:15:11:10 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13.3; rv:126.0) Gecko/20100101 Firefox/126.0" 193.143.1.119 - - [05/Nov/2025:15:13:20 +0330] "GET /.env HTTP/1.1" 301 0 "-" "-" 31.214.174.196 - - [05/Nov/2025:15:14:57 +0330] "POST /wp-cron.php?doing_wp_cron=1762343097.8534040451049804687500 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 31.214.174.196 - - [05/Nov/2025:15:18:40 +0330] "POST /wp-cron.php?doing_wp_cron=1762343320.9262249469757080078125 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 134.209.45.239 - - [05/Nov/2025:15:18:38 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5) AppleWebKit/618.3.5 (KHTML, like Gecko) Version/17.4 Safari/618.3.5" 89.46.110.149 - - [05/Nov/2025:15:22:22 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7596 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13.3; rv:126.0) Gecko/20100101 Firefox/126.0" 193.143.1.119 - - [05/Nov/2025:15:13:25 +0330] "GET /_profiler/phpinfo HTTP/1.1" 301 0 "-" "-" 193.143.1.119 - - [05/Nov/2025:15:13:30 +0330] "GET /info HTTP/1.1" 301 0 "-" "-" 193.143.1.119 - - [05/Nov/2025:15:13:34 +0330] "GET /phpinfo HTTP/1.1" 301 0 "-" "-" 193.143.1.119 - - [05/Nov/2025:15:13:38 +0330] "GET /info.php HTTP/1.1" 301 0 "-" "-" 193.143.1.119 - - [05/Nov/2025:15:13:43 +0330] "GET /phpmyinfo HTTP/1.1" 301 0 "-" "-" 4.240.89.23 - - [05/Nov/2025:15:14:55 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0" 113.192.8.160 - - [05/Nov/2025:15:26:00 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:125.0.1) Gecko/20100101 Firefox/125.0.1" 171.246.22.190 - - [05/Nov/2025:15:29:41 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7597 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3.1 Safari/605.1.15" 103.72.97.210 - - [05/Nov/2025:15:33:31 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7598 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15" 31.214.174.196 - - [05/Nov/2025:15:29:43 +0330] "POST /wp-cron.php?doing_wp_cron=1762343983.9451749324798583984375 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 31.214.174.196 - - [05/Nov/2025:15:33:33 +0330] "POST /wp-cron.php?doing_wp_cron=1762344213.5268750190734863281250 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 31.214.174.196 - - [05/Nov/2025:15:37:26 +0330] "POST /wp-cron.php?doing_wp_cron=1762344446.5859110355377197265625 HTTP/1.1" 200 20 "-" "WordPress/6.8.3; https://optimyar.com" 51.255.71.164 - - [05/Nov/2025:15:37:24 +0330] "POST /xmlrpc.php HTTP/1.1" 503 7598 "http://optimyar.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.96 Safari/537.36"