195.206.105.217 - - [28/Aug/2020:02:10:55 +0200] "GET /wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php HTTP/1.1" 301 350 "harm.at" "Mozilla/5.0 (Linux; Android 5.0.1; SCH-R970 Build/LRX22C) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.84 Mobile Safari/537.36" 145.239.91.37 - - [28/Aug/2020:02:11:10 +0200] "GET /wp-config.php.1 HTTP/1.1" 301 307 "harm.at" "Mozilla/5.0 (X11; U; Linux i686; pl-PL; rv:1.9.0.2) Gecko/20121223 Ubuntu/9.25 (jaunty) Firefox/3.8" 54.38.81.231 - - [28/Aug/2020:02:11:26 +0200] "GET /wp-config.php.swp HTTP/1.1" 301 307 "harm.at" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.93 Safari/537.36" 51.77.135.89 - - [28/Aug/2020:02:11:40 +0200] "GET /wp-config.php.disabled HTTP/1.1" 301 311 "harm.at" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/60.0.3112.78 Chrome/60.0.3112.78 Safari/537.36" 185.220.100.240 - - [28/Aug/2020:02:11:55 +0200] "GET /wp-config.bak HTTP/1.1" 301 306 "harm.at" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36" 95.211.230.211 - - [28/Aug/2020:02:12:10 +0200] "GET /wp-config.php.new HTTP/1.1" 301 307 "harm.at" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_1_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/16D57 MicroMessenger/7.0.5(0x17000523) NetType/WIFI Language/zh_CN" 185.220.102.253 - - [28/Aug/2020:02:12:25 +0200] "GET /wp-config.php.old HTTP/1.1" 301 307 "harm.at" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.154 Safari/537.36 OPR/20.0.1387.91" 62.102.148.68 - - [28/Aug/2020:02:12:40 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 308 "harm.at" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" 179.43.160.234 - - [28/Aug/2020:02:12:55 +0200] "GET /wp-config.php.backup HTTP/1.1" 301 310 "harm.at" "Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/532.9 (KHTML, like Gecko) Chrome/5.0.309.0 Safari/532.9" 184.105.247.196 - - [28/Aug/2020:02:13:57 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 192.241.222.168 - - [28/Aug/2020:04:11:15 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 131.220.6.152 - - [28/Aug/2020:04:55:50 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 162.142.125.39 - - [28/Aug/2020:07:14:50 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 162.142.125.39 - - [28/Aug/2020:07:14:50 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 193.118.53.194 - - [28/Aug/2020:11:49:54 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 209.17.96.50 - - [28/Aug/2020:11:52:24 +0200] "GET / HTTP/1.1" 301 380 "-" "Mozilla/5.0 (compatible; Nimbostratus-Bot/v1.3.2; http://cloudsystemnetworks.com)" 209.17.96.138 - - [28/Aug/2020:11:55:38 +0200] "GET / HTTP/1.1" 301 391 "-" "Mozilla/5.0 (compatible; Nimbostratus-Bot/v1.3.2; http://cloudsystemnetworks.com)" 138.246.253.15 - - [28/Aug/2020:13:35:48 +0200] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.85 Safari/537.36" 128.14.133.58 - - [28/Aug/2020:17:21:57 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 51.81.98.68 - - [28/Aug/2020:17:47:07 +0200] "POST /wp-content/plugins/ioptimization/IOptimize.php?rchk HTTP/1.1" 301 335 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 51.81.98.68 - - [28/Aug/2020:17:47:16 +0200] "GET /wp-content/plugins/ioptimization/uiljkdjxgt.php?x=ooo HTTP/1.1" 301 340 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 80.82.65.74 - - [28/Aug/2020:19:28:43 +0200] "-" 408 - "-" "-" 80.82.65.74 - - [28/Aug/2020:19:29:03 +0200] "-" 408 - "-" "-" 128.14.134.134 - - [28/Aug/2020:20:33:05 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 172.105.89.161 - - [28/Aug/2020:20:39:54 +0200] "OPTIONS / HTTP/1.1" 301 301 "-" "curl/7.65.3" 202.102.144.114 - - [28/Aug/2020:20:43:15 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 180.149.125.168 - - [28/Aug/2020:20:50:07 +0200] "GET / HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" 167.99.180.26 - - [28/Aug/2020:22:55:30 +0200] "GET /api/v1 HTTP/1.1" 301 305 "-" "python-requests/2.22.0" 139.162.152.36 - - [28/Aug/2020:22:55:50 +0200] "GET / HTTP/1.0" 301 388 "-" "-" 192.241.235.7 - - [28/Aug/2020:23:40:09 +0200] "GET /login HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 138.246.253.15 - - [29/Aug/2020:00:07:25 +0200] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.85 Safari/537.36"