34.222.194.75 - - [19/Jul/2020:02:06:27 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 74.82.47.3 - - [19/Jul/2020:02:25:13 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 131.220.6.152 - - [19/Jul/2020:04:26:27 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 46.165.245.154 - - [19/Jul/2020:04:40:58 +0200] "-" 408 - "-" "-" 185.220.100.253 - - [19/Jul/2020:05:58:18 +0200] "GET /wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php HTTP/1.1" 301 350 "harm.at" "Mozilla/5.0 (Linux; Android 9; MHA-AL00 Build/HUAWEIMHA-AL00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/71.0.3578.99 Mobile Safari/537.36 MMWEBID/9772 MicroMessenger/7.0.6.1460(0x27000634) Process/tools NetType/WIFI Language/zh_CN" 87.120.254.105 - - [19/Jul/2020:05:58:33 +0200] "GET /wp-config.php.1 HTTP/1.1" 301 307 "harm.at" "Mozilla/5.0 (Linux; Android 8.1.0; Moto G (5S)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" 87.120.254.105 - - [19/Jul/2020:05:58:36 +0200] "GET /wp-config.php.swp HTTP/1.1" 301 307 "harm.at" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.108 Safari/537.36" 185.220.101.140 - - [19/Jul/2020:05:58:40 +0200] "GET /wp-config.php.disabled HTTP/1.1" 301 311 "harm.at" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3872.0 Safari/537.36 Edg/78.0.244.0" 185.220.101.6 - - [19/Jul/2020:05:58:55 +0200] "GET /wp-config.bak HTTP/1.1" 301 306 "harm.at" "Mozilla/4.1 (compatible; MSIE 5.0; Symbian OS; Nokia 6600;452) Opera 6.20 [en-US]" 54.76.120.237 - - [19/Jul/2020:05:59:10 +0200] "GET /wp-config.php.new HTTP/1.1" 301 307 "harm.at" "Mozilla/5.0 (Linux; Android 9; Pixel 2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" 185.220.101.207 - - [19/Jul/2020:05:59:25 +0200] "GET /wp-config.php.old HTTP/1.1" 301 307 "harm.at" "Mozilla/4.1 (compatible; MSIE 5.0; Symbian OS; Nokia 6600;452) Opera 6.20 [en-US]" 192.42.116.26 - - [19/Jul/2020:05:59:41 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 308 "harm.at" "Mozilla/5.0 (Linux; Android 5.1.1; SM-J111F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" 185.220.101.4 - - [19/Jul/2020:05:59:55 +0200] "GET /wp-config.php.backup HTTP/1.1" 301 310 "harm.at" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" 185.220.101.10 - - [19/Jul/2020:06:00:11 +0200] "GET /wp-config.php.save HTTP/1.1" 301 308 "harm.at" "Mozilla/5.0 (hp-tablet; Linux; hpwOS/3.0.2; U; de-DE) AppleWebKit/534.6 (KHTML, like Gecko) wOSBrowser/234.40.1 Safari/534.6 TouchPad/1.0" 185.220.102.254 - - [19/Jul/2020:06:00:25 +0200] "GET /wp-config.php~ HTTP/1.1" 301 308 "harm.at" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 212.47.229.4 - - [19/Jul/2020:06:00:40 +0200] "GET /wp-config.php_ HTTP/1.1" 301 306 "harm.at" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 YaBrowser/19.6.0.1583 Yowser/2.5 Safari/537.36" 176.10.99.200 - - [19/Jul/2020:06:00:55 +0200] "GET /wp-config.php.orig HTTP/1.1" 301 308 "harm.at" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3889.0 Safari/537.36" 217.182.194.103 - - [19/Jul/2020:06:01:10 +0200] "GET /wp-config.php_orig HTTP/1.1" 301 309 "harm.at" "Mozilla/5.0 (Linux; Android 8.0.0; SM-G930F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36" 109.70.100.25 - - [19/Jul/2020:06:01:25 +0200] "GET /wp-config.php.original HTTP/1.1" 301 311 "harm.at" "Mozilla/5.0 (Linux; Android 9; ONEPLUS A5000) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36" 192.42.116.28 - - [19/Jul/2020:06:01:40 +0200] "GET /wp-config.php_original HTTP/1.1" 301 312 "harm.at" "Baiduspider ( http://www.baidu.com/search/spider.htm)" 51.75.147.167 - - [19/Jul/2020:06:01:55 +0200] "GET /wp-config.php-original HTTP/1.1" 301 311 "harm.at" "Mozilla/5.0 (Linux; Android 9; VTR-AL00 Build/HUAWEIVTR-AL00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/66.0.3359.126 MQQBrowser/6.2 TBS/044807 Mobile Safari/537.36 MMWEBID/6475 MicroMessenger/7.0.6.1460(0x27000634) Process/tools NetType/4G Language/zh_CN" 195.54.160.21 - - [19/Jul/2020:08:15:27 +0200] "POST /api/jsonws/invoke HTTP/1.1" 301 314 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:08:15:27 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:08:15:29 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:08:15:30 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 301 388 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:08:15:31 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 60.190.248.10 - - [19/Jul/2020:15:08:21 +0200] "-" 408 - "-" "-" 115.238.44.237 - - [19/Jul/2020:15:30:52 +0200] "GET / HTTP/1.0" 301 388 "-" "-" 162.243.128.14 - - [19/Jul/2020:18:00:39 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 208.100.26.231 - - [19/Jul/2020:18:14:00 +0200] "GET / HTTP/1.0" 301 388 "-" "-" 208.100.26.231 - - [19/Jul/2020:18:15:49 +0200] "GET / HTTP/1.0" 301 388 "-" "-" 208.100.26.231 - - [19/Jul/2020:18:15:49 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 208.100.26.231 - - [19/Jul/2020:18:15:50 +0200] "GET /nmaplowercheck1595175348 HTTP/1.1" 301 407 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 208.100.26.231 - - [19/Jul/2020:18:15:51 +0200] "GET /evox/about HTTP/1.1" 301 393 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 208.100.26.231 - - [19/Jul/2020:18:15:51 +0200] "GET /HNAP1 HTTP/1.1" 301 388 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 208.100.26.231 - - [19/Jul/2020:18:15:52 +0200] "POST /sdk HTTP/1.1" 301 386 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 208.100.26.231 - - [19/Jul/2020:18:15:53 +0200] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 208.100.26.231 - - [19/Jul/2020:18:15:54 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 195.37.190.77 - - [19/Jul/2020:18:38:26 +0200] "GET /dns-query?dns=AAABAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 441 "-" "Mozilla/5.0 (compatible; DNSResearchBot/2.1; +http://195.37.190.77)" 195.37.190.77 - - [19/Jul/2020:18:38:26 +0200] "POST /dns-query HTTP/1.1" 301 392 "-" "Mozilla/5.0 (compatible; DNSResearchBot/2.1; +http://195.37.190.77)" 163.172.106.236 - - [19/Jul/2020:20:18:13 +0200] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.9.148.194 - - [19/Jul/2020:20:53:57 +0200] "GET /!adminer.php HTTP/1.1" 301 305 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1 Safari/605.1.15" 163.172.161.137 - - [19/Jul/2020:21:02:50 +0200] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 54.191.61.54 - - [19/Jul/2020:23:09:40 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:12:24 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:12:24 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 301 388 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:12:24 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:12:25 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.21 - - [19/Jul/2020:23:12:25 +0200] "POST /api/jsonws/invoke HTTP/1.1" 301 314 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 209.17.97.58 - - [19/Jul/2020:23:13:05 +0200] "GET / HTTP/1.1" 301 385 "-" "Mozilla/5.0 (compatible; Nimbostratus-Bot/v1.3.2; http://cloudsystemnetworks.com)" 80.82.77.227 - - [19/Jul/2020:23:37:33 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 41.93.45.140 - - [20/Jul/2020:01:25:04 +0200] "GET /admin//config.php HTTP/1.1" 301 400 "-" "curl/7.29.0" 131.220.6.156 - - [20/Jul/2020:01:31:24 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36"