CPU load average spikes every hour with CPU 55% and memory 82% only

Hi guys,

Our Digital Ocean droplet's CPU load average spikes every 1-1.5 hour. Here is the the performance graph for the past 24 hours.

Here are some MySQL error logs for 1.5 hours (one cycle) as well as syslog for 1.5 hours (one cycle).

Some folks commented that "our mysql instance is being killed regularly by Linux’s OOM (out of memory) killer. You should review the load consumed by the resources running on the server. Based on experience it’s usually down to a greedy query that causes a resource contention and makes Linux sacrifice the most expensive process."

However, if you look at the syslog, it is because there were a bunch of apache child processes running which crashed mysql. These apache child processes killed the process! They run every 1-1.5 hours! We don't have any cron jobs.

Besides, if you look at the performance graph, even when the cpu load average (1 min) peaks at 20.71, the cpu hit 46.47% only and the memory hit 53%. The highest cpu and memory have never exceeded 57.5% and 88% respectively.

I found many related threads on Google but they don't seem make any sense in my case including using swap, limiting apache child processes, etc. For instance, limiting apache child processes is just fire fighting. We got to find out the crux of the problem which is why there are so many apache child processes running in the first place which only cropped up about 10 days ago.

Also, here is the htop log when the sites were momentarily down. Both cores shot up to 100% momentarily but the CPU stayed below 50%.

Any idea will be very much appreciated!!

Thanks a lot!

BR, Tom

Welcome!
Regarding CPU load - it is rather system load, the sum of several queue lengths, where one is the schedulers run queue that can be seen as a CPU congestion/load, but there are more queues that are mostly dealing with I/O tasks.
So you should also run a iotop, and a ps -fle to find processes that are I/O intensive or blocking.

1 Like

Regarding the apache processes, are they connecting to the mysql?

netstat -a

Is there a limit in the mysql exceeded, like max number of connections?

1 Like

hi there, thank you so much for your reply and suggestions. i ran ps -fle as below but didn't find any anomalies. what do you think?

F S UID        PID  PPID  C PRI  NI ADDR SZ WCHAN  STIME TTY          TIME CMD
4 S root         1     0  0  80   0 - 46282 ep_pol Jul05 ?        00:00:04 /sbin/init
1 S root         2     0  0  80   0 -     0 kthrea Jul05 ?        00:00:00 [kthreadd]
1 S root         3     2  0  80   0 -     0 smpboo Jul05 ?        00:00:01 [ksoftirqd/0]
1 S root         5     2  0  60 -20 -     0 worker Jul05 ?        00:00:00 [kworker/0:0H]
1 S root         7     2  0  80   0 -     0 rcu_gp Jul05 ?        00:00:31 [rcu_sched]
1 S root         8     2  0  80   0 -     0 rcu_gp Jul05 ?        00:00:00 [rcu_bh]
1 S root         9     2  0 -40   - -     0 smpboo Jul05 ?        00:00:00 [migration/0]
5 S root        10     2  0 -40   - -     0 smpboo Jul05 ?        00:00:00 [watchdog/0]
5 S root        11     2  0 -40   - -     0 smpboo Jul05 ?        00:00:00 [watchdog/1]
1 S root        12     2  0 -40   - -     0 smpboo Jul05 ?        00:00:00 [migration/1]
1 S root        13     2  0  80   0 -     0 smpboo Jul05 ?        00:00:02 [ksoftirqd/1]
1 S root        15     2  0  60 -20 -     0 worker Jul05 ?        00:00:00 [kworker/1:0H]
5 S root        16     2  0  80   0 -     0 devtmp Jul05 ?        00:00:00 [kdevtmpfs]
1 S root        17     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [netns]
1 S root        18     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [perf]
1 S root        19     2  0  80   0 -     0 watchd Jul05 ?        00:00:00 [khungtaskd]
1 S root        20     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [writeback]
1 S root        21     2  0  85   5 -     0 ksm_sc Jul05 ?        00:00:00 [ksmd]
1 S root        22     2  0  99  19 -     0 khugep Jul05 ?        00:00:00 [khugepaged]
1 S root        23     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [crypto]
1 S root        24     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [kintegrityd]
1 S root        25     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        26     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [kblockd]
1 S root        27     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [ata_sff]
1 S root        28     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [md]
1 S root        29     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [devfreq_wq]
1 S root        34     2  0  80   0 -     0 kswapd Jul05 ?        00:03:43 [kswapd0]
1 S root        35     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [vmstat]
1 S root        36     2  0  80   0 -     0 fsnoti Jul05 ?        00:00:00 [fsnotify_mark]
1 S root        37     2  0  80   0 -     0 ecrypt Jul05 ?        00:00:00 [ecryptfs-kthrea]
1 S root        53     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [kthrotld]
1 S root        54     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [acpi_thermal_pm]
1 S root        55     2  0  80   0 -     0 wait_w Jul05 ?        00:00:00 [vballoon]
1 S root        56     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        57     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        58     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        59     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        60     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        61     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        62     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        63     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        64     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root        65     2  0  80   0 -     0 scsi_e Jul05 ?        00:00:00 [scsi_eh_0]
1 S root        66     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [scsi_tmf_0]
1 S root        67     2  0  80   0 -     0 scsi_e Jul05 ?        00:00:00 [scsi_eh_1]
1 S root        68     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [scsi_tmf_1]
1 S root        74     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [ipv6_addrconf]
1 S root        87     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [deferwq]
1 S root        88     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [charger_manager]
1 S root       127     2  0  80   0 -     0 scsi_e Jul05 ?        00:00:00 [scsi_eh_2]
1 S root       128     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [scsi_tmf_2]
1 S root       129     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       130     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       135     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       139     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       144     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       148     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       149     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       151     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       154     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [kpsmoused]
1 S root       495     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [raid5wq]
1 S root       524     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [bioset]
1 S root       545     2  0  80   0 -     0 kjourn Jul05 ?        00:00:14 [jbd2/vda1-8]
1 S root       546     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [ext4-rsv-conver]
1 S root       606     2  0  60 -20 -     0 worker Jul05 ?        00:00:00 [kworker/1:1H]
4 S root       628     1  0  80   0 -  9563 ep_pol Jul05 ?        00:00:03 /lib/systemd/systemd-journald
1 S root       641     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [iscsi_eh]
1 S root       659     2  0  80   0 -     0 kaudit Jul05 ?        00:00:00 [kauditd]
1 S root       666     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [ib_addr]
4 S root       669     1  0  80   0 - 23693 poll_s Jul05 ?        00:00:00 /sbin/lvmetad -f
1 S root       702     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [ib_mcast]
1 S root       703     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [ib_nl_sa_wq]
1 S root       705     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [ib_cm]
1 S root       711     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [iw_cm_wq]
4 S root       712     1  0  80   0 - 10578 ep_pol Jul05 ?        00:00:00 /lib/systemd/systemd-udevd
1 S root       713     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [rdma_cm]
1 S root       819     2  0  60 -20 -     0 rescue Jul05 ?        00:00:00 [kvm-irqfd-clean]
4 S systemd+   959     1  0  80   0 - 25080 ep_pol Jul05 ?        00:00:00 /lib/systemd/systemd-timesyncd
1 S root      1039     2  0  60 -20 -     0 worker Jul05 ?        00:00:00 [kworker/0:1H]
1 S root      1404     1  0  80   0 -  1304 hrtime Jul05 ?        00:00:03 /sbin/iscsid
5 S root      1405     1  0  70 -10 -  1429 poll_s Jul05 ?        00:00:16 /sbin/iscsid
4 S do-agent  1407     1  0  80   0 - 79456 futex_ Jul05 ?        00:00:18 /opt/digitalocean/bin/do-agent --syslog
4 S message+  1410     1  0  80   0 - 10722 ep_pol Jul05 ?        00:00:00 /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-ac
0 S root      1419     1  0  80   0 -  1098 poll_s Jul05 ?        00:00:00 /usr/sbin/acpid
4 S daemon    1421     1  0  80   0 -  6511 hrtime Jul05 ?        00:00:00 /usr/sbin/atd -f
4 S root      1425     1  0  80   0 - 95682 futex_ Jul05 ?        00:00:00 /usr/bin/lxcfs /var/lib/lxcfs/
4 S root      1435     1  0  80   0 -  7136 ep_pol Jul05 ?        00:00:00 /lib/systemd/systemd-logind
4 S root      1438     1  0  80   0 - 68617 poll_s Jul05 ?        00:00:02 /usr/lib/accountsservice/accounts-daemon
4 S syslog    1445     1  0  80   0 - 64097 poll_s Jul05 ?        00:00:01 /usr/sbin/rsyslogd -n
4 S root      1456     1  0  80   0 -  6932 hrtime Jul05 ?        00:00:00 /usr/sbin/cron -f
4 S root      1499     1  0  80   0 - 16378 poll_s Jul05 ?        00:00:00 /usr/sbin/sshd -D
4 S root      1510     1  0  80   0 - 43337 poll_s Jul05 ?        00:00:00 /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait
4 S root      1544     1  0  80   0 - 69272 poll_s Jul05 ?        00:00:00 /usr/lib/policykit-1/polkitd --no-debug
4 S root      1556     1  0  80   0 -  3663 poll_s Jul05 tty1     00:00:00 /sbin/agetty --noclear tty1 linux
4 S root      1559     1  0  80   0 -  3617 poll_s Jul05 ttyS0    00:00:00 /sbin/agetty --keep-baud 115200 38400 9600 ttyS0 vt220
1 S root      1569     1  0  80   0 -  3342 poll_s Jul05 ?        00:00:00 /sbin/mdadm --monitor --pid-file /run/mdadm/monitor.pid --daemonise --scan --syslo
1 S opendkim  1587     1  0  80   0 - 55396 poll_s Jul05 ?        00:00:01 /usr/sbin/opendkim -x /etc/opendkim.conf -u opendkim -P /var/run/opendkim/opendkim
5 S root      1599     1  0  80   0 -  4868 hrtime Jul05 ?        00:00:03 /usr/sbin/irqbalance --pid=/var/run/irqbalance.pid
5 S root      1651     1  0  80   0 - 146748 poll_s Jul05 ?       00:01:06 /usr/bin/python3 /usr/bin/fail2ban-server -s /var/run/fail2ban/fail2ban.sock -p /v
5 S root      1711     1  0  80   0 - 145393 poll_s Jul05 ?       00:00:15 /usr/sbin/apache2 -k start
1 S www-data  1714     1  0  80   0 -  4922 poll_s Jul05 ?        00:00:04 /usr/bin/htcacheclean -d 120 -p /var/cache/apache2/mod_cache_disk -l 300M -n
4 S root      1861     1  0  80   0 - 16351 ep_pol Jul05 ?        00:00:00 /usr/lib/postfix/sbin/master
4 S postfix   1869  1861  0  80   0 - 16909 ep_pol Jul05 ?        00:00:00 qmgr -l -t unix -u
1 S root     25893     2  0  80   0 -     0 worker 06:09 ?        00:00:00 [kworker/0:0]
1 S root     26072     2  0  80   0 -     0 worker 06:20 ?        00:00:00 [kworker/u4:1]
1 S root     26700     2  0  80   0 -     0 worker 06:23 ?        00:00:00 [kworker/0:2]
4 S mysql    26789     1  2  80   0 - 395558 poll_s 06:23 ?       00:02:57 /usr/sbin/mysqld
4 S postfix  27586  1861  0  80   0 - 16868 ep_pol 06:55 ?        00:00:00 pickup -l -t unix -u -c
1 S root     27782     2  0  80   0 -     0 worker 07:09 ?        00:00:00 [kworker/1:0]
5 S www-data 27987  1711  0  80   0 - 181455 ep_pol 07:31 ?       00:00:18 /usr/sbin/apache2 -k start
5 S www-data 28012  1711  1  80   0 - 183087 SYSC_s 07:32 ?       00:00:22 /usr/sbin/apache2 -k start
5 S www-data 28041  1711  0  80   0 - 178823 SYSC_s 07:35 ?       00:00:15 /usr/sbin/apache2 -k start
1 S root     28182     2  0  80   0 -     0 worker 07:39 ?        00:00:00 [kworker/1:1]
1 S root     28226     2  0  80   0 -     0 worker 07:52 ?        00:00:00 [kworker/u4:2]
5 S www-data 28275  1711  0  80   0 - 159579 SYSC_s 08:04 ?       00:00:01 /usr/sbin/apache2 -k start
4 R root     28282  1499  0  80   0 - 23200 -      08:05 ?        00:00:00 sshd: root@pts/0
4 S root     28284     1  0  80   0 -  9218 ep_pol 08:05 ?        00:00:00 /lib/systemd/systemd --user
5 S root     28287 28284  0  80   0 - 52145 sigtim 08:05 ?        00:00:00 (sd-pam)
1 S root     28288     2  0  80   0 -     0 worker 08:05 ?        00:00:00 [kworker/1:2]
4 S root     28360 28282  0  80   0 -  5366 wait   08:05 pts/0    00:00:00 -bash
5 S www-data 28381  1711  1  80   0 - 183169 SYSC_s 08:05 ?       00:00:03 /usr/sbin/apache2 -k start
5 S www-data 28394  1711  3  80   0 - 186362 SYSC_s 08:07 ?       00:00:02 /usr/sbin/apache2 -k start
5 S www-data 28395  1711  2  80   0 - 180570 SYSC_s 08:07 ?       00:00:02 /usr/sbin/apache2 -k start
5 S www-data 28396  1711  0  80   0 - 155768 SYSC_s 08:07 ?       00:00:00 /usr/sbin/apache2 -k start
5 S www-data 28401  1711  0  80   0 - 148468 SYSC_s 08:07 ?       00:00:00 /usr/sbin/apache2 -k start
5 S www-data 28402  1711  1  80   0 - 170247 SYSC_s 08:07 ?       00:00:00 /usr/sbin/apache2 -k start
0 R root     28407 28360  0  80   0 -  9021 -      08:08 pts/0    00:00:00 ps -fle

hi there again, thanks for the suggestion. i also ran netstat -a as below but don't find anything that seems to have limited mysql from running properly. any idea?

Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 localhost:mysql         *:*                     LISTEN
tcp        0      0 *:ssh                   *:*                     LISTEN
tcp        0      0 *:smtp                  *:*                     LISTEN
tcp        0     64 139.59.96.33:ssh        ti0022q162-5579.b:50031 ESTABLISHED
tcp6       0      0 [::]:http               [::]:*                  LISTEN
tcp6       0      0 [::]:ssh                [::]:*                  LISTEN
tcp6       0      0 [::]:smtp               [::]:*                  LISTEN
tcp6       0      0 [::]:https              [::]:*                  LISTEN
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56132 TIME_WAIT
tcp6       0      0 139.59.96.33:https      msnbot-207-46-13-:16494 ESTABLISHED
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56162 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56130 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56134 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56163 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56166 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56149 TIME_WAIT
tcp6       0      0 139.59.96.33:http       139.59.96.33:51610      TIME_WAIT
tcp6       0      0 139.59.96.33:https      ti0022q162-5579.b:50046 ESTABLISHED
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56135 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56131 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56167 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56168 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56165 TIME_WAIT
tcp6       0      0 139.59.96.33:http       203186170046.ctin:56133 TIME_WAIT
Active UNIX domain sockets (servers and established)
Proto RefCnt Flags       Type       State         I-Node   Path
unix  2      [ ACC ]     STREAM     LISTENING     18087    private/smtp
unix  2      [ ]         DGRAM                    361238   /run/user/0/systemd/notify
unix  2      [ ACC ]     STREAM     LISTENING     361239   /run/user/0/systemd/private
unix  2      [ ACC ]     SEQPACKET  LISTENING     9454     /run/udev/control
unix  2      [ ACC ]     STREAM     LISTENING     361243   /run/user/0/snapd-session-agent.socket
unix  2      [ ACC ]     STREAM     LISTENING     12258    /var/lib/lxd/unix.socket
unix  3      [ ]         DGRAM                    9447     /run/systemd/notify
unix  2      [ ]         DGRAM                    9448     /run/systemd/cgroups-agent
unix  2      [ ACC ]     STREAM     LISTENING     9449     /run/systemd/private
unix  2      [ ACC ]     STREAM     LISTENING     9453     /run/lvm/lvmetad.socket
unix  14     [ ]         DGRAM                    9455     /run/systemd/journal/dev-log
unix  2      [ ACC ]     STREAM     LISTENING     9456     /run/systemd/journal/stdout
unix  7      [ ]         DGRAM                    9457     /run/systemd/journal/socket
unix  2      [ ]         DGRAM                    9463     /run/systemd/journal/syslog
unix  2      [ ACC ]     STREAM     LISTENING     9470     /run/lvm/lvmpolld.socket
unix  2      [ ACC ]     STREAM     LISTENING     18090    private/relay
unix  2      [ ]         DGRAM                    13756    /var/spool/postfix/dev/log
unix  2      [ ACC ]     STREAM     LISTENING     12264    /run/snapd.socket
unix  2      [ ACC ]     STREAM     LISTENING     18093    public/showq
unix  2      [ ACC ]     STREAM     LISTENING     18096    private/error
unix  2      [ ACC ]     STREAM     LISTENING     18099    private/retry
unix  2      [ ACC ]     STREAM     LISTENING     18102    private/discard
unix  2      [ ACC ]     STREAM     LISTENING     18105    private/local
unix  2      [ ACC ]     STREAM     LISTENING     18108    private/virtual
unix  2      [ ACC ]     STREAM     LISTENING     18111    private/lmtp
unix  2      [ ACC ]     STREAM     LISTENING     18114    private/anvil
unix  2      [ ACC ]     STREAM     LISTENING     18049    public/pickup
unix  2      [ ACC ]     STREAM     LISTENING     18117    private/scache
unix  2      [ ACC ]     STREAM     LISTENING     18053    public/cleanup
unix  2      [ ACC ]     STREAM     LISTENING     18056    public/qmgr
unix  2      [ ACC ]     STREAM     LISTENING     18060    private/tlsmgr
unix  2      [ ACC ]     STREAM     LISTENING     18063    private/rewrite
unix  2      [ ACC ]     STREAM     LISTENING     18120    private/maildrop
unix  2      [ ACC ]     STREAM     LISTENING     18123    private/uucp
unix  2      [ ACC ]     STREAM     LISTENING     18127    private/ifmail
unix  2      [ ACC ]     STREAM     LISTENING     18130    private/bsmtp
unix  2      [ ACC ]     STREAM     LISTENING     18133    private/scalemail-backend
unix  2      [ ACC ]     STREAM     LISTENING     18136    private/mailman
unix  2      [ ACC ]     STREAM     LISTENING     18066    private/bounce
unix  2      [ ACC ]     STREAM     LISTENING     18069    private/defer
unix  2      [ ACC ]     STREAM     LISTENING     12257    /run/uuidd/request
unix  2      [ ACC ]     STREAM     LISTENING     12265    /run/snapd-snap.socket
unix  2      [ ACC ]     STREAM     LISTENING     12266    /var/run/dbus/system_bus_socket
unix  2      [ ACC ]     STREAM     LISTENING     12256    /run/acpid.socket
unix  2      [ ACC ]     STREAM     LISTENING     12942    @ISCSIADM_ABSTRACT_NAMESPACE
unix  2      [ ACC ]     STREAM     LISTENING     14175    /var/run/opendkim/opendkim.sock
unix  2      [ ACC ]     STREAM     LISTENING     14290    /var/run/fail2ban/fail2ban.sock
unix  2      [ ACC ]     STREAM     LISTENING     18072    private/trace
unix  2      [ ACC ]     STREAM     LISTENING     345610   /var/run/mysqld/mysqld.sock
unix  2      [ ACC ]     STREAM     LISTENING     18075    private/verify
unix  2      [ ACC ]     STREAM     LISTENING     18078    public/flush
unix  2      [ ACC ]     STREAM     LISTENING     18081    private/proxymap
unix  2      [ ACC ]     STREAM     LISTENING     18084    private/proxywrite
unix  2      [ ]         DGRAM                    15841
unix  3      [ ]         DGRAM                    10447
unix  3      [ ]         STREAM     CONNECTED     10087    /run/systemd/journal/stdout
unix  2      [ ]         DGRAM                    9651
unix  3      [ ]         STREAM     CONNECTED     14550    /run/systemd/journal/stdout
unix  2      [ ]         DGRAM                    14285
unix  3      [ ]         STREAM     CONNECTED     15261
unix  3      [ ]         STREAM     CONNECTED     13040
unix  3      [ ]         STREAM     CONNECTED     11650
unix  3      [ ]         DGRAM                    10099
unix  3      [ ]         STREAM     CONNECTED     15262    /var/run/dbus/system_bus_socket
unix  3      [ ]         DGRAM                    10098
unix  3      [ ]         DGRAM                    10097
unix  2      [ ]         DGRAM                    15840
unix  3      [ ]         DGRAM                    10446
unix  3      [ ]         STREAM     CONNECTED     15673    /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     13067
unix  3      [ ]         STREAM     CONNECTED     18100
unix  3      [ ]         STREAM     CONNECTED     18062
unix  2      [ ]         DGRAM                    13058
unix  3      [ ]         STREAM     CONNECTED     18098
unix  3      [ ]         STREAM     CONNECTED     18097
unix  3      [ ]         STREAM     CONNECTED     16285    /var/run/dbus/system_bus_socket
unix  3      [ ]         STREAM     CONNECTED     16284
unix  3      [ ]         STREAM     CONNECTED     18095
unix  3      [ ]         STREAM     CONNECTED     18094
unix  3      [ ]         STREAM     CONNECTED     18138
unix  3      [ ]         STREAM     CONNECTED     18137
unix  3      [ ]         STREAM     CONNECTED     18092
unix  3      [ ]         STREAM     CONNECTED     18061
unix  3      [ ]         STREAM     CONNECTED     15672
unix  3      [ ]         STREAM     CONNECTED     18091
unix  3      [ ]         STREAM     CONNECTED     18135
unix  3      [ ]         STREAM     CONNECTED     18134
unix  3      [ ]         STREAM     CONNECTED     15152    /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     18089
unix  3      [ ]         STREAM     CONNECTED     18088
unix  3      [ ]         STREAM     CONNECTED     18132
unix  3      [ ]         STREAM     CONNECTED     15254    /var/run/dbus/system_bus_socket
unix  3      [ ]         STREAM     CONNECTED     18131
unix  3      [ ]         STREAM     CONNECTED     14865
unix  3      [ ]         STREAM     CONNECTED     13068
unix  3      [ ]         STREAM     CONNECTED     18086
unix  3      [ ]         STREAM     CONNECTED     18115
unix  3      [ ]         STREAM     CONNECTED     8920
unix  3      [ ]         STREAM     CONNECTED     18116
unix  3      [ ]         STREAM     CONNECTED     18113
unix  2      [ ]         DGRAM                    13580
unix  3      [ ]         STREAM     CONNECTED     8921     /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     10272
unix  3      [ ]         STREAM     CONNECTED     18054
unix  3      [ ]         STREAM     CONNECTED     18112
unix  3      [ ]         STREAM     CONNECTED     18058
unix  3      [ ]         STREAM     CONNECTED     18109
unix  3      [ ]         STREAM     CONNECTED     13069    /var/run/dbus/system_bus_socket
unix  2      [ ]         DGRAM                    361233
unix  3      [ ]         STREAM     CONNECTED     18057
unix  3      [ ]         STREAM     CONNECTED     18110
unix  3      [ ]         STREAM     CONNECTED     13424
unix  3      [ ]         STREAM     CONNECTED     18107
unix  2      [ ]         DGRAM                    14182
unix  2      [ ]         DGRAM                    10298
unix  3      [ ]         STREAM     CONNECTED     10273    /run/systemd/journal/stdout
unix  2      [ ]         DGRAM                    361224
unix  3      [ ]         STREAM     CONNECTED     18106
unix  3      [ ]         STREAM     CONNECTED     13046    /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     361210
unix  2      [ ]         DGRAM                    362393
unix  3      [ ]         STREAM     CONNECTED     18103
unix  3      [ ]         STREAM     CONNECTED     18104
unix  3      [ ]         STREAM     CONNECTED     18101
unix  2      [ ]         DGRAM                    13188
unix  3      [ ]         STREAM     CONNECTED     362401   /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     18055
unix  3      [ ]         STREAM     CONNECTED     18068
unix  3      [ ]         STREAM     CONNECTED     18070
unix  3      [ ]         STREAM     CONNECTED     18129
unix  3      [ ]         STREAM     CONNECTED     18071
unix  3      [ ]         STREAM     CONNECTED     18051
unix  2      [ ]         DGRAM                    10092
unix  3      [ ]         STREAM     CONNECTED     18128
unix  3      [ ]         STREAM     CONNECTED     13730
unix  3      [ ]         STREAM     CONNECTED     13009
unix  2      [ ]         DGRAM                    16950
unix  3      [ ]         STREAM     CONNECTED     18073
unix  3      [ ]         STREAM     CONNECTED     15569
unix  3      [ ]         STREAM     CONNECTED     18126
unix  3      [ ]         STREAM     CONNECTED     18064
unix  3      [ ]         STREAM     CONNECTED     18074
unix  3      [ ]         STREAM     CONNECTED     16616
unix  2      [ ]         DGRAM                    8726
unix  3      [ ]         STREAM     CONNECTED     18125
unix  3      [ ]         STREAM     CONNECTED     18048
unix  3      [ ]         DGRAM                    10096
unix  3      [ ]         STREAM     CONNECTED     18076
unix  3      [ ]         STREAM     CONNECTED     14347    /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     14480
unix  3      [ ]         STREAM     CONNECTED     18077
unix  3      [ ]         STREAM     CONNECTED     13539
unix  2      [ ]         DGRAM                    353894
unix  3      [ ]         STREAM     CONNECTED     18079
unix  2      [ ]         DGRAM                    12941
unix  3      [ ]         STREAM     CONNECTED     15586    /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     18122
unix  3      [ ]         STREAM     CONNECTED     18080
unix  3      [ ]         STREAM     CONNECTED     14281    /var/run/dbus/system_bus_socket
unix  3      [ ]         STREAM     CONNECTED     18121
unix  3      [ ]         STREAM     CONNECTED     18047
unix  3      [ ]         STREAM     CONNECTED     18082
unix  3      [ ]         STREAM     CONNECTED     13362    /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     18119
unix  3      [ ]         STREAM     CONNECTED     18083
unix  2      [ ]         DGRAM                    16831
unix  3      [ ]         STREAM     CONNECTED     18118
unix  3      [ ]         STREAM     CONNECTED     18067
unix  3      [ ]         STREAM     CONNECTED     18050
unix  3      [ ]         STREAM     CONNECTED     14551    /run/systemd/journal/stdout
unix  3      [ ]         STREAM     CONNECTED     18065
unix  3      [ ]         STREAM     CONNECTED     18085
unix  3      [ ]         STREAM     CONNECTED     14541

@tomjansen

You should consider reading this entire discussion (blog topic) of a real-life situation of random server spikes on a server running a LAMP web application:

4 Likes

hi @Neo, thank you for the post which i hope will point me to the right direction.

in reference to your post #39, i am wondering how they e.g. Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36 showed up in your access.log. i would be very grateful if you could share with me that line which was identified as one of the chinese bots you mentioned. thanks a lot!

if you look at two sessions of access.log (0921-0924 and 1632-1634) when the cpu load averages spiked, there are bot logs like bingbot, googlebot, zoominfo bot, ahrefs bot, etc which i believe are legit. some of unidentified sources like 115.124.35.231 - - [01/Jul/2020:09:21:51 +0000] “GET / HTTP/1.1” 301 580 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:76.0) Gecko/20100101 Firefox/76.0” seem to a legit user as well, do they? do you suggest i block those IPs? any idea? thank you so much!

84.202.100.14 - - [01/Jul/2020:09:21:41 +0000] “GET /wp-json/wp/v2/categories?perpage=100&orderby=count&order=desc&fields=id%2Cname&locale=user HTTP/1.1” 200 1192 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
20.42.108.88 - - [01/Jul/2020:09:21:41 +0000] “GET /wp-content/plugins/ppus/up.php HTTP/1.1” 404 87361 “-” “python-requests/2.24.0”
20.42.108.88 - - [01/Jul/2020:09:21:42 +0000] “GET /098.php HTTP/1.1” 301 576 “-” “python-requests/2.24.0”
20.42.108.88 - - [01/Jul/2020:09:21:43 +0000] “GET /098.php HTTP/1.1” 301 3830 “-” “python-requests/2.24.0”
20.42.108.88 - - [01/Jul/2020:09:21:45 +0000] “GET /098.php HTTP/1.1” 404 87361 “-” “python-requests/2.24.0”
20.42.108.88 - - [01/Jul/2020:09:21:46 +0000] “GET /V5.php HTTP/1.1” 301 574 “-” “python-requests/2.24.0”
20.42.108.88 - - [01/Jul/2020:09:21:47 +0000] “GET /V5.php HTTP/1.1” 301 3829 “-” “python-requests/2.24.0”
84.202.100.14 - - [01/Jul/2020:09:21:47 +0000] “POST /wp-json/wp/v2/posts/4375?locale=user HTTP/1.1” 200 37835 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
185.187.30.14 - - [01/Jul/2020:09:21:48 +0000] “GET / HTTP/1.1” 301 580 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”
185.187.30.14 - - [01/Jul/2020:09:21:48 +0000] “GET / HTTP/1.1” 301 580 “-” “Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36”
185.187.30.13 - - [01/Jul/2020:09:21:48 +0000] “GET / HTTP/1.1” 301 580 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”
20.42.108.88 - - [01/Jul/2020:09:21:48 +0000] “GET /V5.php HTTP/1.1” 404 87361 “-” “python-requests/2.24.0”
84.202.100.14 - - [01/Jul/2020:09:21:48 +0000] “POST /wp-admin/post.php?post=4375&action=edit&meta-box-loader=1&meta-box-loader-nonce=d09249632a&locale=user HTTP/1.1” 302 523 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
20.42.108.88 - - [01/Jul/2020:09:21:50 +0000] “GET /newlicense.php HTTP/1.1” 301 592 “-” “python-requests/2.24.0”
185.187.30.14 - - [01/Jul/2020:09:21:50 +0000] “GET / HTTP/1.1” 301 579 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”
84.202.100.14 - - [01/Jul/2020:09:21:49 +0000] “GET /wp-admin/post.php?post=4375&action=edit&message=4 HTTP/1.1” 200 201719 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
115.124.35.231 - - [01/Jul/2020:09:21:51 +0000] “GET / HTTP/1.1” 301 580 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:76.0) Gecko/20100101 Firefox/76.0”
185.187.30.14 - - [01/Jul/2020:09:21:49 +0000] “GET / HTTP/1.1” 200 17343 “-” “Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36”
185.187.30.13 - - [01/Jul/2020:09:21:49 +0000] “GET / HTTP/1.1” 200 17322 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”
185.187.30.14 - - [01/Jul/2020:09:21:49 +0000] “GET / HTTP/1.1” 200 17312 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”
139.59.96.33 - - [01/Jul/2020:09:21:51 +0000] “POST /wp-cron.php?doingwpcron=1593595311.0411748886108398437500 HTTP/1.1” 200 3320 “https://www.azinity.com/wp-cron.php?doingwpcron=1593595311.0411748886108398437500” “WordPress/5.4.2; https://www.azinity.com”
84.202.100.14 - - [01/Jul/2020:09:21:50 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/index.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
20.42.108.88 - - [01/Jul/2020:09:21:51 +0000] “GET /newlicense.php HTTP/1.1” 301 3838 “-” “python-requests/2.24.0”
185.187.30.14 - - [01/Jul/2020:09:21:51 +0000] “GET / HTTP/1.1” 200 17285 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”
20.42.108.88 - - [01/Jul/2020:09:21:52 +0000] “GET /newlicense.php HTTP/1.1” 404 87361 “-” “python-requests/2.24.0”
::1 - - [01/Jul/2020:09:21:53 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
20.42.108.88 - - [01/Jul/2020:09:21:53 +0000] “GET /wp-content/plugins/theme-configurator/mini.php HTTP/1.1” 301 654 “-” “python-requests/2.24.0”
54.36.148.218 - - [01/Jul/2020:09:21:53 +0000] “GET /products/KM%252d947-%E6%B1%BD%E8%BD%A6%E8%BE%85%E5%8A%A9%E9%95%9C%E5%AD%90%28%E4%BE%9B%E4%B8%A4%E5%90%A8%E8%BD%A6%29-%D0%A419%7B47%7D22%7B47%7D25%7B47%7D27MM–%E2%80%93-%E7%94%B5%E9%95%80%E9%93%AC.html HTTP/1.1” 301 711 “-” “Mozilla/5.0 (compatible; AhrefsBot/6.1; +http://ahrefs.com/robot/)”
::1 - - [01/Jul/2020:09:21:54 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
20.42.108.88 - - [01/Jul/2020:09:21:54 +0000] “GET /wp-content/plugins/theme-configurator/mini.php HTTP/1.1” 301 3869 “-” “python-requests/2.24.0”
20.42.108.88 - - [01/Jul/2020:09:21:56 +0000] “GET /wp-content/plugins/theme-configurator/mini.php HTTP/1.1” 404 87361 “-” “python-requests/2.24.0”
::1 - - [01/Jul/2020:09:21:56 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
::1 - - [01/Jul/2020:09:21:57 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
::1 - - [01/Jul/2020:09:21:58 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
::1 - - [01/Jul/2020:09:21:59 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
::1 - - [01/Jul/2020:09:22:00 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
20.42.108.88 - - [01/Jul/2020:09:22:00 +0000] “GET /wp-content/plugins/widget-logic/mini.php HTTP/1.1” 301 642 “-” “python-requests/2.24.0”
20.42.108.88 - - [01/Jul/2020:09:22:03 +0000] “GET /wp-content/plugins/widget-logic/mini.php HTTP/1.1” 301 3863 “-” “python-requests/2.24.0”
20.42.108.88 - - [01/Jul/2020:09:22:04 +0000] “GET /wp-content/plugins/widget-logic/mini.php HTTP/1.1” 404 87361 “-” “python-requests/2.24.0”
218.102.220.232 - - [01/Jul/2020:09:22:04 +0000] “GET /zh-hant/ HTTP/1.1” 200 12294 “https://www.google.com/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:06 +0000] “GET /wp-includes/css/dist/block-library/style.min.css?ver=5.4.2 HTTP/1.1” 200 8045 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:06 +0000] “GET /wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.1.9 HTTP/1.1” 200 4810 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:06 +0000] “GET /wp-content/plugins/cssigniter-shortcodes/src/style.css?ver=2.3.2 HTTP/1.1” 200 11324 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/socials-ignited/css/font-awesome.css?ver=4.7.0 HTTP/1.1” 200 7842 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/social-media-widget/socialwidget.css?ver=5.4.2 HTTP/1.1” 200 862 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/custom-facebook-feed-pro/css/cff-style.css?ver=3.13.1 HTTP/1.1” 200 15818 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/socials-ignited/css/style.css?ver=5.4.2 HTTP/1.1” 200 641 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/sitepress-multilingual-cms/templates/language-switchers/legacy-list-horizontal/style.css?ver=1 HTTP/1.1” 200 1250 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/common/css/global.css?ver=2.5.5 HTTP/1.1” 200 939 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/css/base.css?ver=2.5.5 HTTP/1.1” 200 3721 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/wpml-translation-management/res/css/admin-bar-style.css?ver=2.9.8 HTTP/1.1” 200 4245 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/css/flexslider.css?ver=2.5.5 HTTP/1.1” 200 1869 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/css/mmenu.css?ver=2.5.5 HTTP/1.1” 200 4796 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/css/magnific.css?ver=2.5.5 HTTP/1.1” 200 2248 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/colors/teal.css?ver=2.5.5 HTTP/1.1” 200 1008 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/style.css?ver=2.5.5 HTTP/1.1” 200 14412 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-includes/js/jquery/jquery.js?ver=1.12.4-wp HTTP/1.1” 200 34283 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1 HTTP/1.1” 200 4431 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/uploads/siteorigin-widgets/sow-features-default-dcaa1c8ba163.css?ver=5.4.2 HTTP/1.1” 200 1150 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/so-widgets-bundle/widgets/features/css/style.css?ver=1.17.0 HTTP/1.1” 200 756 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/siteorigin-panels/css/front-flex.min.css?ver=2.11.0 HTTP/1.1” 200 717 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/so-widgets-bundle/icons/fontawesome/style.css?ver=5.4.2 HTTP/1.1” 200 1778 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=5.1.9 HTTP/1.1” 200 4456 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/cssigniter-shortcodes/src/js/scripts.js?ver=2.3.2 HTTP/1.1” 200 1422 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/cssigniter-shortcodes/src/js/jquery.flexslider.js?ver=2.2.2 HTTP/1.1” 200 11878 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/plugins/custom-facebook-feed-pro/js/cff-scripts.js?ver=3.13.1 HTTP/1.1” 200 64466 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-includes/js/comment-reply.min.js?ver=5.4.2 HTTP/1.1” 200 1531 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/js/jquery.mmenu.min.all.js?ver=2.5.5 HTTP/1.1” 200 7910 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/panel/scripts/jquery.fitvids.js?ver=2.5.5 HTTP/1.1” 200 1828 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/js/jquery.isotope.js?ver=2.5.5 HTTP/1.1” 200 10153 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:07 +0000] “GET /wp-content/themes/business3ree/js/jquery.magnific-popup.js?ver=2.5.5 HTTP/1.1” 200 14402 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/themes/business3ree/js/magnific-init.js?ver=2.5.5 HTTP/1.1” 200 777 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/themes/business3ree/js/scripts.js?ver=2.5.5 HTTP/1.1” 200 1623 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-includes/js/wp-embed.min.js?ver=5.4.2 HTTP/1.1” 200 1140 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/uploads/flags/hk%20flag.png HTTP/1.1” 200 688 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/uploads/2016/02/workbook-12050441920-1920x550.jpg HTTP/1.1” 200 148077 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/uploads/2016/08/mgi-logo.png HTTP/1.1” 200 23509 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/plugins/sitepress-multilingual-cms/res/flags/en.png HTTP/1.1” 200 906 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-includes/js/wp-emoji-release.min.js?ver=5.4.2 HTTP/1.1” 200 5070 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/uploads/2017/05/imageedit14475962635.png HTTP/1.1” 200 90157 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/plugins/so-widgets-bundle/widgets/features/css/fonts/feature-background.woff HTTP/1.1” 200 2149 “https://www.kennethchaucpa.com/wp-content/plugins/so-widgets-bundle/widgets/features/css/style.css?ver=1.17.0” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/uploads/2017/04/kenneth-logo2.png HTTP/1.1” 200 84397 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
218.102.220.232 - - [01/Jul/2020:09:22:08 +0000] “GET /wp-content/uploads/2015/09/hong-kong-12233901920-1920x550.jpg HTTP/1.1” 200 112324 “https://www.kennethchaucpa.com/zh-hant/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:22:10 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1178 “https://www.azinity.com/wp-admin/index.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:22:18 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/index.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:22:21 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 722 “https://www.azinity.com/wp-admin/index.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
::1 - - [01/Jul/2020:09:22:29 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
104.131.186.50 - - [01/Jul/2020:09:22:31 +0000] “GET /wp-login.php HTTP/1.1” 200 2220 “-” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
104.131.186.50 - - [01/Jul/2020:09:22:33 +0000] “POST /wp-login.php HTTP/1.1” 200 2621 “-” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
104.131.186.50 - - [01/Jul/2020:09:22:34 +0000] “POST /xmlrpc.php HTTP/1.1” 403 463 “-” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
102.114.197.199 - - [01/Jul/2020:09:22:38 +0000] “POST /xmlrpc.php HTTP/1.1” 403 3803 “-” “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)”
139.59.96.33 - - [01/Jul/2020:09:22:38 +0000] “POST /wp-cron.php?doingwpcron=1593595358.8872148990631103515625 HTTP/1.1” 200 3320 “https://www.azinity.com/wp-cron.php?doingwpcron=1593595358.8872148990631103515625” “WordPress/5.4.2; https://www.azinity.com”
102.114.197.199 - - [01/Jul/2020:09:22:38 +0000] “POST /wp-login.php HTTP/1.1” 200 6579 “-” “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)”
84.202.100.14 - - [01/Jul/2020:09:22:52 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/index.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
35.196.38.103 - - [01/Jul/2020:09:22:55 +0000] “GET /category/news/ HTTP/1.0” 200 7122 “-” “ZoominfoBot (zoominfobot at zoominfo dot com)”
210.213.127.95 - - [01/Jul/2020:09:22:58 +0000] “POST /xmlrpc.php HTTP/1.1” 403 3977 “-” “-”
66.249.79.144 - - [01/Jul/2020:09:23:05 +0000] “GET /zh-hant/%E8%81%AF%E7%B5%A1%E6%88%91%E5%80%91/ HTTP/1.1” 200 11375 “-” “Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.92 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET / HTTP/1.1” 200 6731 “-” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-includes/css/dist/block-library/style.min.css?ver=5.3.4 HTTP/1.1” 200 6469 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.1.6 HTTP/1.1” 200 985 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/css/base.css?ver=2.0.2 HTTP/1.1” 200 3122 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/css/flexslider.css?ver=2.0.2 HTTP/1.1” 200 1740 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/common/css/global.css?ver=2.0.2 HTTP/1.1” 200 901 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/css/mmenu.css?ver=2.0.2 HTTP/1.1” 200 6439 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/assets/fontawesome/css/all.min.css?ver=2.0.2 HTTP/1.1” 200 12152 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/css/magnific.css?ver=2.0.2 HTTP/1.1” 200 2182 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/css/slick.css?ver=2.0.2 HTTP/1.1” 200 868 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1 HTTP/1.1” 200 4365 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/style.css?ver=2.0.2 HTTP/1.1” 200 14850 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=5.1.6 HTTP/1.1” 200 4344 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-includes/js/jquery/jquery.js?ver=1.12.4-wp HTTP/1.1” 200 34129 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/js/superfish.js?ver=2.0.2 HTTP/1.1” 200 2679 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/plugins/wp-smushit/app/assets/js/smush-lazy-load.min.js?ver=3.3.2 HTTP/1.1” 200 4043 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/js/jquery.mmenu.oncanvas.js?ver=2.0.2 HTTP/1.1” 200 5322 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/js/jquery.mmenu.navbars.js?ver=2.0.2 HTTP/1.1” 200 1511 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/js/jquery.mmenu.offcanvas.js?ver=2.0.2 HTTP/1.1” 200 2728 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:06 +0000] “GET /wp-content/themes/brittany/brittany/js/jquery.mmenu.autoheight.js?ver=2.0.2 HTTP/1.1” 200 1264 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/themes/brittany/brittany/js/jquery.flexslider.js?ver=2.0.2 HTTP/1.1” 200 12166 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/themes/brittany/brittany/js/jquery.fitvids.js?ver=2.0.2 HTTP/1.1” 200 1806 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/themes/brittany/brittany/js/jquery.matchHeight.js?ver=2.0.2 HTTP/1.1” 200 3384 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/themes/brittany/brittany/js/scripts.js?ver=2.0.2 HTTP/1.1” 200 2493 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/themes/brittany/brittany/js/jquery.magnific-popup.js?ver=2.0.2 HTTP/1.1” 200 14314 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/themes/brittany/brittany/js/slick.js?ver=2.0.2 HTTP/1.1” 200 13702 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-includes/js/wp-embed.min.js?ver=5.3.4 HTTP/1.1” 200 1089 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-includes/js/wp-emoji-release.min.js?ver=5.3.4 HTTP/1.1” 200 4977 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/uploads/2016/04/shutterstock237798787.jpg HTTP/1.1” 200 128723 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/uploads/2016/04/5-1920x850.jpg HTTP/1.1” 200 160294 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:07 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 4343 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
112.118.7.200 - - [01/Jul/2020:09:23:08 +0000] “GET /wp-content/uploads/2016/04/imageedit13906533807.png HTTP/1.1” 200 58851 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/uploads/2017/06/shutterstock393318367.jpg HTTP/1.1” 200 1566132 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:08 +0000] “GET /wp-content/themes/brittany/brittany/assets/fontawesome/webfonts/fa-brands-400.woff2 HTTP/1.1” 200 72375 “http://www.chewing.com.hk/wp-content/themes/brittany/brittany/assets/fontawesome/css/all.min.css?ver=2.0.2” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:08 +0000] “GET /wp-content/themes/brittany/brittany/assets/fontawesome/webfonts/fa-solid-900.woff2 HTTP/1.1” 200 74611 “http://www.chewing.com.hk/wp-content/themes/brittany/brittany/assets/fontawesome/css/all.min.css?ver=2.0.2” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:08 +0000] “GET /wp-content/themes/betheme/functions/builder/assets/builder.css?ver=1593595388 HTTP/1.1” 200 6376 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:08 +0000] “GET /wp-content/plugins/wp-live-chat-support/includes/blocks/wplc-inline-chat-box/includes/blocks/wplc-inline-chat-box/editor.css?ver=8.1.9 HTTP/1.1” 404 96589 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-admin/post.php?post=4375&action=edit HTTP/1.1” 200 203606 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
139.59.96.33 - - [01/Jul/2020:09:23:08 +0000] “POST /wp-cron.php?doingwpcron=1593595388.9101660251617431640625 HTTP/1.1” 200 3320 “https://www.azinity.com/wp-cron.php?doingwpcron=1593595388.9101660251617431640625” “WordPress/5.4.2; https://www.azinity.com”
84.202.100.14 - - [01/Jul/2020:09:23:08 +0000] “GET /wp-content/plugins/wp-live-chat-support/includes/blocks/wplc-chat-box/includes/blocks/wplc-chat-box/editor.css?ver=8.1.9 HTTP/1.1” 404 92806 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:09 +0000] “GET /wp-content/plugins/wp-live-chat-support/includes/blocks/wplc-chat-box/includes/blocks/wplc-chat-box/block.js?ver=8.1.9 HTTP/1.1” 404 92806 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/uploads/2017/06/shutterstock77987791.jpg HTTP/1.1” 200 918845 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/uploads/2016/04/4.jpg HTTP/1.1” 200 1465823 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:09 +0000] “GET /wp-content/plugins/wp-live-chat-support/includes/blocks/wplc-inline-chat-box/includes/blocks/wplc-inline-chat-box/block.js?ver=8.1.9 HTTP/1.1” 404 77943 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:09 +0000] “GET /wp-content/plugins/wp-live-chat-support/includes/blocks/wplc-inline-chat-box/includes/blocks/wplc-inline-chat-box/wplcfunctions.js?ver=8.1.9 HTTP/1.1” 404 77943 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
112.118.7.200 - - [01/Jul/2020:09:23:07 +0000] “GET /wp-content/uploads/2017/06/shutterstock600532826.jpg HTTP/1.1” 200 1073696 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:10 +0000] “GET /wp-content/plugins/wp-live-chat-support/includes/blocks/wplc-inline-chat-box/includes/blocks/wplc-inline-chat-box/wplcfunctions.js?ver=8.1.9 HTTP/1.1” 404 92806 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
112.118.7.200 - - [01/Jul/2020:09:23:10 +0000] “GET /wp-content/uploads/2017/05/cropped-chewing-logo-100x100.jpg HTTP/1.1” 200 3441 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:10 +0000] “GET /wp-content/uploads/2017/06/Religious-Item-360x540.jpg HTTP/1.1” 200 25037 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:10 +0000] “GET /wp-content/uploads/2017/06/Jewels-Item-360x540.jpg HTTP/1.1” 200 18225 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
112.118.7.200 - - [01/Jul/2020:09:23:10 +0000] “GET /wp-content/uploads/2017/06/Dresses-360x540.jpg HTTP/1.1” 200 20525 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:10 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1178 “https://www.azinity.com/wp-admin/index.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:11 +0000] “GET /wp-content/themes/betheme/functions/builder/assets/builder.js?ver=1593595388 HTTP/1.1” 200 11127 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:11 +0000] “GET /wp-json/wp/v2/ HTTP/1.1” 200 105507 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:11 +0000] “GET /wp-admin/admin-ajax.php?action=smushnotices3supportrequired HTTP/1.1” 200 466 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:12 +0000] “GET /wp-json/wp/v2/media/4376?context=edit&locale=user HTTP/1.1” 200 13978 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:12 +0000] “GET /wp-json/wp/v2/users/me?locale=user HTTP/1.1” 200 5140 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:13 +0000] “GET /wp-json/wp/v2/categories?perpage=100&orderby=name&order=asc&fields=id%2Cname%2Cparent&locale=user HTTP/1.1” 200 1346 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
112.118.7.200 - - [01/Jul/2020:09:23:13 +0000] “GET /contact/ HTTP/1.1” 200 5741 “http://www.chewing.com.hk/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:13 +0000] “GET /wp-json/wp/v2/taxonomies/category?context=edit&locale=user HTTP/1.1” 200 2062 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:13 +0000] “GET /wp-json/wp/v2/categories?perpage=100&orderby=count&order=desc&fields=id%2Cname&locale=user HTTP/1.1” 200 1756 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:14 +0000] “GET /wp-content/uploads/2020/07/word-cloud-6799331280-216x146.png HTTP/1.1” 304 203 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
139.59.96.33 - - [01/Jul/2020:09:23:13 +0000] “POST /wp-cron.php?doingwpcron=1593595393.2736299037933349609375 HTTP/1.1” 200 3283 “https://www.winlandjm.com/wp-cron.php?doingwpcron=1593595393.2736299037933349609375” “WordPress/5.1.6; https://www.winlandjm.com”
35.185.70.58 - - [01/Jul/2020:09:23:12 +0000] “GET /product/galvanized-steel-medicine-cabinet-3/ HTTP/1.0” 200 14766 “-” “ZoominfoBot (zoominfobot at zoominfo dot com)”
112.118.7.200 - - [01/Jul/2020:09:23:14 +0000] “GET /wp-content/plugins/contact-form-7/images/ajax-loader.gif HTTP/1.1” 200 1131 “http://www.chewing.com.hk/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.1.6” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:14 +0000] “GET /wp-content/uploads/2020/07/word-cloud-6799331280.png HTTP/1.1” 304 204 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
::1 - - [01/Jul/2020:09:23:18 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
66.249.79.90 - - [01/Jul/2020:09:23:19 +0000] “GET /app-presentation-creative-website/ HTTP/1.1” 200 24025 “-” “Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.92 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)”
84.202.100.14 - - [01/Jul/2020:09:23:19 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/index.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
::1 - - [01/Jul/2020:09:23:21 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
::1 - - [01/Jul/2020:09:23:22 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
84.202.100.14 - - [01/Jul/2020:09:23:22 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 722 “https://www.azinity.com/wp-admin/index.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
::1 - - [01/Jul/2020:09:23:23 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
112.118.7.200 - - [01/Jul/2020:09:23:23 +0000] “GET /wp-content/uploads/2017/05/chewing-logo-transparent.png HTTP/1.1” 200 59901 “http://www.chewing.com.hk/contact/” “Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:25 +0000] “GET /wp-json/yoast/v1/prominentwords?word=keyword+research+best+practices HTTP/1.1” 200 2109 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:25 +0000] “GET /wp-json/wp/v2/tags?perpage=100&orderby=count&order=desc&fields=id%2Cname&include=2945&locale=user HTTP/1.1” 200 1278 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:25 +0000] “GET /wp-json/wp/v2/taxonomies/posttag?context=edit&locale=user HTTP/1.1” 200 2571 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:25 +0000] “GET /wp-json/yoast/v1/prominentwords?word=keyword+research HTTP/1.1” 200 1500 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:26 +0000] “GET /wp-json/yoast/v1/prominentwords?word=research+best+practices HTTP/1.1” 200 1521 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
162.158.165.32 - - [01/Jul/2020:09:23:24 +0000] “GET /wp-login.php HTTP/1.1” 200 6104 “-” “Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.80 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:09:23:26 +0000] “GET /wp-json/yoast/v1/prominentwords?word=search+intent HTTP/1.1” 200 1491 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
172.69.135.216 - - [01/Jul/2020:09:23:25 +0000] “POST /wp-cron.php?doingwpcron=1593595405.2614119052886962890625 HTTP/1.1” 200 3973 “https://www.brighteroptical.com/wp-cron.php?doingwpcron=1593595405.2614119052886962890625” “WordPress/5.4.2; https://www.brighteroptical.com”
84.202.100.14 - - [01/Jul/2020:09:23:27 +0000] “GET /wp-json/yoast/v1/prominentwords?word=search+volume HTTP/1.1” 200 1491 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:27 +0000] “GET /wp-json/yoast/v1/prominentwords?word=search+terms HTTP/1.1” 200 1488 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:27 +0000] “GET /wp-json/yoast/v1/prominentwords?word=long-tail+keywords HTTP/1.1” 200 1506 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:28 +0000] “GET /wp-json/yoast/v1/prominentwords?word=search+intent+and+search+volume HTTP/1.1” 200 1545 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:28 +0000] “GET /wp-json/yoast/v1/prominentwords?word=buy+black+sneakers+in+california HTTP/1.1” 200 1548 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:29 +0000] “GET /wp-json/yoast/v1/prominentwords?word=keyword+research+best+practices+search HTTP/1.1” 200 1566 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:29 +0000] “GET /wp-json/yoast/v1/prominentwords?word=keywords HTTP/1.1” 200 1476 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
14.192.212.100 - - [01/Jul/2020:09:23:29 +0000] “POST /xmlrpc.php HTTP/1.1” 403 446 “-” “-”
84.202.100.14 - - [01/Jul/2020:09:23:30 +0000] “GET /wp-json/yoast/v1/prominentwords?word=keyword HTTP/1.1” 200 1473 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
89.43.139.166 - - [01/Jul/2020:09:23:30 +0000] “GET /wp-login.php HTTP/1.1” 200 5411 “-” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
84.202.100.14 - - [01/Jul/2020:09:23:30 +0000] “GET /wp-json/yoast/v1/prominentwords?word=best+practices HTTP/1.1” 200 1494 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”
84.202.100.14 - - [01/Jul/2020:09:23:30 +0000] “GET /wp-json/yoast/v1/prominentwords?word=buy+black+sneakers HTTP/1.1” 200 1506 “https://www.azinity.com/wp-admin/post.php?post=4375&action=edit” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 Edg/83.0.478.56”

139.59.96.33 - - [01/Jul/2020:16:32:02 +0000] “POST /wp-cron.php?doingwpcron=1593621122.5536470413208007812500 HTTP/1.1” 200 3283 “https://www.winlandjm.com/wp-cron.php?doing_wp_cron=1593621122.5536470413208007812500” “WordPress/5.1.6; https://www.winlandjm.com”
46.229.168.134 - - [01/Jul/2020:16:32:01 +0000] “GET /product/wall-mounted-mailbox-26/ HTTP/1.1” 200 15496 “-” “Mozilla/5.0 (compatible; SemrushBot/6~bl; +http://www.semrush.com/bot.html)”
104.196.143.164 - - [01/Jul/2020:16:32:10 +0000] “GET /handles/ HTTP/1.0” 200 7645 “-” “ZoominfoBot (zoominfobot at zoominfo dot com)”
35.231.241.106 - - [01/Jul/2020:16:32:13 +0000] “GET /zh-hant/ HTTP/1.0” 200 6526 “-” “ZoominfoBot (zoominfobot at zoominfo dot com)”
84.202.100.14 - - [01/Jul/2020:16:32:26 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/edit.php?s&post_status=all&post_type=page&m=202001&seo_filter&readability_filter&paged=1” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
35.231.241.106 - - [01/Jul/2020:16:32:48 +0000] “GET /portfolio/c-cotton-cordage/ HTTP/1.0” 200 5796 “-” “ZoominfoBot (zoominfobot at zoominfo dot com)”
139.59.96.33 - - [01/Jul/2020:16:32:53 +0000] “POST /wp-cron.php?doingwpcron=1593621173.5667989253997802734375 HTTP/1.1” 200 3320 “https://www.azinity.com/wp-cron.php?doing_wp_cron=1593621173.5667989253997802734375” “WordPress/5.4.2; https://www.azinity.com”
84.202.100.14 - - [01/Jul/2020:16:32:53 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/edit.php?s&post_status=all&post_type=page&m=202001&seo_filter&readability_filter&paged=1” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:16:32:57 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 722 “https://www.azinity.com/wp-admin/edit.php?s&post_status=all&post_type=page&m=202001&seo_filter&readability_filter&paged=1” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
35.231.241.106 - - [01/Jul/2020:16:32:58 +0000] “GET /portfolio/i-nylon-cordage/ HTTP/1.0” 200 5851 “-” “ZoominfoBot (zoominfobot at zoominfo dot com)”
104.196.143.164 - - [01/Jul/2020:16:33:18 +0000] “GET /zh-hant/ HTTP/1.0” 200 7810 “-” “ZoominfoBot (zoominfobot at zoominfo dot com)”
139.59.96.33 - - [01/Jul/2020:16:33:27 +0000] “POST /wp-cron.php?doingwpcron=1593621207.6146600246429443359375 HTTP/1.1” 200 166 “http://www.chewing.com.hk/wp-cron.php?doing_wp_cron=1593621207.6146600246429443359375” “WordPress/5.3.4; http://www.chewing.com.hk”
54.36.148.155 - - [01/Jul/2020:16:33:27 +0000] “GET / HTTP/1.1” 200 6675 “-” “Mozilla/5.0 (compatible; AhrefsBot/6.1; +http://ahrefs.com/robot/)”
172.69.134.143 - - [01/Jul/2020:16:33:28 +0000] “GET /static/ecommerce/144/144080/js/scriptaculous/slider.js HTTP/1.1” 301 694 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
84.202.100.14 - - [01/Jul/2020:16:33:28 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/edit.php?s&post_status=all&post_type=page&m=202001&seo_filter&readability_filter&paged=1” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
54.36.149.68 - - [01/Jul/2020:16:33:28 +0000] “GET /robots.txt HTTP/1.1” 200 4099 “-” “Mozilla/5.0 (compatible; AhrefsBot/6.1; +http://ahrefs.com/robot/)”
172.69.134.143 - - [01/Jul/2020:16:33:29 +0000] “GET /static/ecommerce/144/144080/js/scriptaculous/slider.js HTTP/1.1” 301 4218 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
162.158.167.192 - - [01/Jul/2020:16:33:30 +0000] “POST /wp-cron.php?doingwpcron=1593621210.5525879859924316406250 HTTP/1.1” 200 3973 “https://www.brighteroptical.com/wp-cron.php?doing_wp_cron=1593621210.5525879859924316406250” “WordPress/5.4.2; https://www.brighteroptical.com”
162.158.165.162 - - [01/Jul/2020:16:33:32 +0000] “GET /static/ecommerce/144/144080/skin/frontend/rwd/ivresponsive/js/lib/matchmedia.js HTTP/1.1” 301 746 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
162.158.165.162 - - [01/Jul/2020:16:33:33 +0000] “GET /static/ecommerce/144/144080/skin/frontend/rwd/ivresponsive/js/lib/matchmedia.js HTTP/1.1” 301 4244 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
162.158.166.131 - - [01/Jul/2020:16:33:34 +0000] “GET /static/ecommerce/144/144080/js/calendar/calendar-setup.js HTTP/1.1” 301 700 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
162.158.166.131 - - [01/Jul/2020:16:33:34 +0000] “GET /static/ecommerce/144/144080/js/calendar/calendar-setup.js HTTP/1.1” 301 4221 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
172.69.135.12 - - [01/Jul/2020:16:33:36 +0000] “GET /static/ecommerce/144/144080/js/lib/ccard.js HTTP/1.1” 301 672 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
172.69.135.12 - - [01/Jul/2020:16:33:38 +0000] “GET /static/ecommerce/144/144080/js/lib/ccard.js HTTP/1.1” 301 4207 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
162.158.167.50 - - [01/Jul/2020:16:33:39 +0000] “GET /static/ecommerce/144/144080/js/mage/cookies.js HTTP/1.1” 301 678 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
162.158.167.50 - - [01/Jul/2020:16:33:40 +0000] “GET /static/ecommerce/144/144080/js/mage/cookies.js HTTP/1.1” 301 4210 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
125.131.98.219 - - [01/Jul/2020:16:33:42 +0000] “GET /wp-login.php HTTP/1.1” 301 564 “-” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
125.131.98.219 - - [01/Jul/2020:16:33:43 +0000] “GET /wp-login.php HTTP/1.1” 200 5486 “http://www.allyintl.com/wp-login.php” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
125.131.98.219 - - [01/Jul/2020:16:33:44 +0000] “GET ///?author=1 HTTP/1.1” 301 558 “-” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
172.68.146.148 - - [01/Jul/2020:16:33:44 +0000] “GET /static/ecommerce/144/144080/skin/frontend/rwd/ivresponsive/js/lib/matchmedia.js HTTP/1.1” 404 75939 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
125.131.98.219 - - [01/Jul/2020:16:33:45 +0000] “GET /?author=1 HTTP/1.1” 301 3394 “http://www.allyintl.com///?author=1” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
162.158.167.6 - - [01/Jul/2020:16:33:45 +0000] “GET /static/ecommerce/144/144080/js/calendar/calendar-setup.js HTTP/1.1” 404 75939 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
162.158.165.66 - - [01/Jul/2020:16:33:47 +0000] “GET /static/ecommerce/144/144080/js/lib/ccard.js HTTP/1.1” 404 75939 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
125.131.98.219 - - [01/Jul/2020:16:33:47 +0000] “GET /?author=1 HTTP/1.1” 404 23007 “https://www.allyintl.com/?author=1” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
162.158.165.78 - - [01/Jul/2020:16:33:49 +0000] “GET /static/ecommerce/144/144080/js/mage/cookies.js HTTP/1.1” 404 75939 “-” “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”
125.131.98.219 - - [01/Jul/2020:16:33:50 +0000] “GET ///wp-json/wp/v2/users/ HTTP/1.1” 301 580 “-” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
125.131.98.219 - - [01/Jul/2020:16:33:52 +0000] “GET /wp-json/wp/v2/users/ HTTP/1.1” 200 4142 “http://www.allyintl.com///wp-json/wp/v2/users/” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
::1 - - [01/Jul/2020:16:33:54 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
18.230.13.131 - - [01/Jul/2020:16:33:54 +0000] “POST /xmlrpc.php HTTP/1.1” 403 463 “-” “Mozilla/5.0 (X11; Ubuntu; Linux x8664; rv:62.0) Gecko/20100101 Firefox/62.0”
139.59.96.33 - - [01/Jul/2020:16:33:56 +0000] “POST /wp-cron.php?doingwpcron=1593621235.6483728885650634765625 HTTP/1.1” 200 3320 “https://www.azinity.com/wp-cron.php?doingwpcron=1593621235.6483728885650634765625” “WordPress/5.4.2; https://www.azinity.com”
84.202.100.14 - - [01/Jul/2020:16:33:55 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/edit.php?s&poststatus=all&posttype=page&m=202001&seofilter&readabilityfilter&paged=1” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
84.202.100.14 - - [01/Jul/2020:16:33:59 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 722 “https://www.azinity.com/wp-admin/edit.php?s&poststatus=all&posttype=page&m=202001&seofilter&readabilityfilter&paged=1” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”
157.55.39.80 - - [01/Jul/2020:16:34:00 +0000] “GET /how-to-sell-home-decor-online/ HTTP/1.1” 200 33149 “-” “Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)”
::1 - - [01/Jul/2020:16:34:07 +0000] “OPTIONS * HTTP/1.0” 200 126 “-” “Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)”
58.10.101.92 - - [01/Jul/2020:16:34:15 +0000] “POST /xmlrpc.php HTTP/1.1” 403 442 “-” “-”
66.249.68.40 - - [01/Jul/2020:16:34:23 +0000] “GET / HTTP/1.1” 301 277 “-” “Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.92 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)”
66.249.79.181 - - [01/Jul/2020:16:34:24 +0000] “GET / HTTP/1.1” 200 6580 “-” “Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.92 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)”
84.202.100.14 - - [01/Jul/2020:16:34:30 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 1286 “https://www.azinity.com/wp-admin/edit.php?s&poststatus=all&posttype=page&m=202001&seofilter&readability_filter&paged=1” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36”```

hi @neo again, i have singled out the unidentified sources from the access log when the cpu load spike struck between 0921-0924. however, i don't find anything similar in the latter session where a cpu load spike also struck. could they be the culprit then?

115.124.35.231 - - [01/Jul/2020:09:21:51 +0000] “GET / HTTP/1.1” 301 580 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:76.0) Gecko/20100101 Firefox/76.0”
185.187.30.14 - - [01/Jul/2020:09:21:49 +0000] “GET / HTTP/1.1” 200 17343 “-” “Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36”
185.187.30.13 - - [01/Jul/2020:09:21:49 +0000] “GET / HTTP/1.1” 200 17322 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”
185.187.30.14 - - [01/Jul/2020:09:21:49 +0000] “GET / HTTP/1.1” 200 17312 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”
185.187.30.14 - - [01/Jul/2020:09:21:51 +0000] “GET / HTTP/1.1” 200 17285 “-” “Mozilla/5.0 (Linux; U; Android 4.1.2; ja-jp; SC-06D Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30”

Yes, @tomjansen..... generally load spikes in LAMP web apps, based on my experience, are mostly caused by rouge bots.

It's a lot of detective work to understand "what is a bot, and what is not a bot", which I do with custom software I have written, based on models of bot-like behavior I have created.

It's a lot of work... welcome to 2020 :slight_smile:

1 Like

hi @neo, thanks for your comment. shall we get that software from you?

br, tom

Sorry, the custom software I wrote for detecting and classifying rouge bots is not available. It's custom code which integrates into our LAMP application and MySQL DB; and it does more than just detect and classify bot activity, it was originally written for a CSA visualization project I was working on.

You will need to write your own or acquire some similar software; or hire some expert to do it for you.

1 Like

@tomjansen

FWIW, here is a technical paper we published on parts of that project:

https://www.researchgate.net/publication/320008976_Virtualized_Cyberspace_-_Visualizing_Patterns_Anomalies_for_Cognitive_Cyber_Situational_Awareness

1 Like

hi @Neo, what a good read. thanks for that.

say today i identify some malicious IPs and add them to .htaccess but what if other malicious bots strike tomorrow? would this be like fire fighting?

also, do you think if migrating to another server or service provider would help?

any suggestion would be highly appreciated!

br, tom

@tomjansen

My view is that it is best to gain "situational awareness" (SA) before developing a mitigation strategy or tactics.

The model to consider was developed by US fighter pilots many years ago, and it still holds true today.

OBSERVE, ORIENT, DECIDE, ACT.

This is called the OODA loop.

By instrumenting your application and acquiring SA (situational awareness), the OBSERVE and ORIENT part of OODA, you can then DECIDE what to do and then ACT.

It sounds to me you have not yet acquired SA, and only amateurs would advise on what actions to take before they have acquired SA.

Professionals acquire SA first before they propose controls and migration strategies.

Hope this helps is some small way.....

1 Like

hi @Neo, i appreciate the time you have spent on writing me.

indeed, i am an amateur. i ain't a server guy. i just want to get it fixed as soon as i can so that i can get back to my daily routines which is building websites.

anyways, all the best to you.

br,
tom

1 Like

You too, @tomjansen......

Sorry I cannot advise you on what to do. I've been doing this for decades, and I always try to gain as close to full SA as possible before coming up with a migration strategy.

This approach has served me very well over a long career in this area.

Often, the fastest way to solve a problem is to slow down and understand what exact problem exists before trying to solve it :). The solution is usually the easy part. Finding the exact problem is the harder part. This requires instrumentation, observation and analysis. That's how I have worked for over three decades in this field.

Cheers!

2 Likes

Hi @Neo,

I'd like to share with some updates and be grateful if you could shed some light on this.

Today I have come to realize that the access log I pasted earlier was an hour behind because the time the DO graphs indicates in our local computer time which UTC+1 and the server's time is UTC. No wonder I didn't find anything. I have found many malicious IP addresses as follows which originate from China. However, they vary from time to time so it will literally be futile to block these IPs. So far we blocked ten IPs but they keep changing! What do you suggest in this case?

Thank you so much.

BR,
Tom

123.138.77.50 - - [12/Jul/2020:07:21:01 +0000] "GET / HTTP/1.1" 200 6713 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /HACK.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /lwy.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /photo3.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /aaa.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /text.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /hackmyth.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /2005.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /2009091519484277962.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /zhuanbi.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:03 +0000] "GET /include/dama.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:04 +0000] "GET /plus/postocer.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:05 +0000] "GET /jyhack.com.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
139.59.96.33 - - [12/Jul/2020:07:21:06 +0000] "POST /wp-cron.php?doing_wp_cron=1594538465.8975160121917724609375 HTTP/1.1" 200 3309 "https://www.winlandjm.com/wp-cron.php?doing_wp_cron=1594538465.8975160121917724609375" "WordPress/5.1.6; https://www.winlandjm.com"
93.113.110.111 - - [12/Jul/2020:07:21:05 +0000] "GET /wp-login.php HTTP/1.1" 200 4825 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /201055151920.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /maoadai.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /%e5%85%a8%e9%83%a8%e5%9c%b0%e5%9d%80.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /jun.asa HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /feng.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /andx.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /op.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /jxx.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /img.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /ely.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
93.113.110.111 - - [12/Jul/2020:07:21:07 +0000] "POST /wp-login.php HTTP/1.1" 200 5268 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
123.138.77.50 - - [12/Jul/2020:07:21:06 +0000] "GET /SeVen.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
93.113.110.111 - - [12/Jul/2020:07:21:11 +0000] "POST /xmlrpc.php HTTP/1.1" 403 3512 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
123.138.77.50 - - [12/Jul/2020:07:21:07 +0000] "GET /yin.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:07 +0000] "GET /dn.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:07 +0000] "GET /lk.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:11 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:07 +0000] "GET /w0ai1uo.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:07 +0000] "GET /honglinjin.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:07 +0000] "GET /include/tags.class.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:07 +0000] "GET /zgd.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:07 +0000] "GET /Alan.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:12 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
::1 - - [12/Jul/2020:07:21:15 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /youhao.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /page.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /2.aspx HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /admin2.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /2009122623418349.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:13 +0000] "GET /QQgroup68988741.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /00.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /top3.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /1.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /newst.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /shaomiao.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /886.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /2008723182517855.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /9999.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /5.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:15 +0000] "GET /123.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /min.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:15 +0000] "GET /huangdi.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:15 +0000] "GET /molu.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
84.202.100.14 - - [12/Jul/2020:07:21:12 +0000] "POST /hotcrafthobby/wp-admin/admin-ajax.php HTTP/1.1" 200 1357 "https://clients.azinity.com/hotcrafthobby/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36"
123.138.77.50 - - [12/Jul/2020:07:21:12 +0000] "GET /xz.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /123456.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /test.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /200962614559578.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:15 +0000] "GET /long.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:14 +0000] "GET /yy.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:15 +0000] "GET /admind.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:17 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /by_ld.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /Romantic.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /H4ckSo1di3r.HtML HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /11.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /q1367706820.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /zijing.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /hq.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /logi.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /ac.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /admin/mk.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /f.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /amao.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /hackjie.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /Bx.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /exit.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /2009-kof97.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /mao.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /dd.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:08 +0000] "GET /yt9077.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /hooey.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /yz.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /wuqing.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /zyp.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:10 +0000] "GET /hx.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /T2sec.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:10 +0000] "GET /hack-a.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /1.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /ba.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:09 +0000] "GET /editor.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:20 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:10 +0000] "GET /about.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:10 +0000] "GET /Draksec.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:10 +0000] "GET /plus/vps.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:10 +0000] "GET /aspx.aspx HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:10 +0000] "GET /GZ.HTM HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:21 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
::1 - - [12/Jul/2020:07:21:22 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
::1 - - [12/Jul/2020:07:21:23 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:16 +0000] "GET /aaa.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /heiyu.asp HTTP/1.1" 500 3143 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:21 +0000] "GET /love.htm HTTP/1.1" 500 3143 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:17 +0000] "GET /init.php HTTP/1.1" 500 3143 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:24 +0000] "GET /read.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:24 +0000] "GET /oos.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:28 +0000] "GET /xylp.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:28 +0000] "GET /new.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:28 +0000] "GET /l.d.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:25 +0000] "GET /89745999.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:28 +0000] "GET /admintt.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:28 +0000] "GET /nijiuraimas1713.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:28 +0000] "GET /amscracker.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:28 +0000] "GET /uploads/memberlogin.inc.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /20106120219686.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /1162.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /hackes.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /uploads/page.funcs.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /aslog.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /jedy.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /bySeRDaR.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /check.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:29 +0000] "GET /lt.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /downmin.inc.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /L.D.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /NewFo./1.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /Jim.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /aoyun.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /liyun.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /wanx00.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /luangtuan.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:30 +0000] "GET /blue.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /wp-update.php HTTP/1.1" 500 3143 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /data/indray.php HTTP/1.1" 500 3143 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:31 +0000] "GET /user.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:31 +0000] "GET /bu.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:31 +0000] "GET /ying.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:31 +0000] "GET /myups.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:31 +0000] "GET /xt.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:31 +0000] "GET /bye.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /xt.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /admin/newsoug.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
162.158.165.246 - - [12/Jul/2020:07:21:32 +0000] "GET /ecommerce/air-optix-aqua-2976.php HTTP/1.1" 500 6745 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
::1 - - [12/Jul/2020:07:21:32 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /UNDEADLEGION.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /123.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /UploadFiles/201111.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /wack.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /conn.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /ce.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:32 +0000] "GET /yongheng.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /K7y2le.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /user.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /images/log.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
172.245.50.248 - - [12/Jul/2020:07:21:11 +0000] "GET /taxation HTTP/1.1" 500 6776 "-" "AccompanyBot"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /cx/up1oad.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /swat.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:17 +0000] "GET /Yn.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /2.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /Ddos.html HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /test1.jsp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /db.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /fuck.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /yulegu.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /hack.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /HuangBigGhost-Fuck-DaiLaiLaMa-CNN-BBC-NTV-RTL.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /story.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /help.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /js.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:17 +0000] "GET /wsry.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /drt.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /tags.class.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /help.asp? HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /feng.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:17 +0000] "GET /ws.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /wan.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /test.jsp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:33 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /help.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /dshao.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /Hacker_a.htm HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /jc.html HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /inside.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /files/articlesfichiers/robots.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /aa.html HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /tts.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /cm.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /dan.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /2010622145030102.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /wsq.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /searche.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:17 +0000] "GET /ab.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /xx.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /abcd.html HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /soojoy.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /drt.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /test.txt HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /saro.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /zhwlhybdll.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /alert.txt HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /cange520.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /abc.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /200845172350599.asa HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /96cN.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:19 +0000] "GET /xiaobai.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /editor.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /cmd.txt HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /lazciz.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /tongyi.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:19 +0000] "GET /heiye.htm HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:19 +0000] "GET /ad.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /Waiting.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:19 +0000] "GET /20106313245325262.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:19 +0000] "GET /sever.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:18 +0000] "GET /ad_usertopjs.htm HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /end.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:19 +0000] "GET /defaut.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:34 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /aben.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /m.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:19 +0000] "GET /ab.php HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /20107281245887528.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /leishang.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:19 +0000] "GET /about.htm HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:34 +0000] "GET /hchk.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:20 +0000] "GET /add.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:20 +0000] "GET /china.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:20 +0000] "GET /renpinyouwenti.html HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /admin.htm HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:35 +0000] "GET /2.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:35 +0000] "GET /THE.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:22 +0000] "GET /zc.htm HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:21 +0000] "GET /addmanagerok.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:21 +0000] "GET /lpt2.dream.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:22 +0000] "GET /12345.html HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /816.txt HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /cmd.asa HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /moshimo667.htm HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:35 +0000] "GET /20107281294210895.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:35 +0000] "GET /company.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:22 +0000] "GET /Joker.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:35 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:35 +0000] "GET /hacker.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:36 +0000] "GET /opChinaReload.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /ouran.asp HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /ouran.html HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /Seven.html HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:23 +0000] "GET /zencart1.php HTTP/1.1" 500 3004 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:36 +0000] "GET /nokcah.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:36 +0000] "GET /coli.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:36 +0000] "GET /anonph.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:36 +0000] "GET /go.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:36 +0000] "GET /life.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:36 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:36 +0000] "GET /520.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:36 +0000] "GET /cmd.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
157.55.39.138 - - [12/Jul/2020:07:21:36 +0000] "GET /index.php?languageid=1&pageid=76 HTTP/1.1" 500 3003 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /jyhack.com.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /fuck.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /2009820225332869.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /fuck.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /hack.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /hack4.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
157.55.39.138 - - [12/Jul/2020:07:21:37 +0000] "GET /wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=5.4.5 HTTP/1.1" 200 45283 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /xiaojian.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /ant1.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:37 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /UserLogin.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:37 +0000] "GET /1.jsp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /hackbs.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /404.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /back.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /est.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:16 +0000] "GET /root.asp HTTP/1.1" 404 16808 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:17 +0000] "GET /wangshiruyan.asp HTTP/1.1" 404 20416 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /xxxx.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /2.jsp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:17 +0000] "GET /20071222213940994.asa HTTP/1.1" 404 20416 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /hacked.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /123.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
157.55.39.138 - - [12/Jul/2020:07:21:38 +0000] "GET /wp-content/plugins/LayerSlider/static/layerslider/css/layerslider.css?ver=6.7.0 HTTP/1.1" 200 4213 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /2010122784038041.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /su.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /homepage.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /shuai.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /517.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:38 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
157.55.39.138 - - [12/Jul/2020:07:21:38 +0000] "GET /wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=5.4.5 HTTP/1.1" 200 45256 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /ngsst.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /lou.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /hacked.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /23026583.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:38 +0000] "GET /nannan.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:39 +0000] "GET /heike/zhuangbi.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:39 +0000] "GET /fish.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:39 +0000] "GET /download.aspx HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:39 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
157.55.39.138 - - [12/Jul/2020:07:21:39 +0000] "GET /wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=5.4.5 HTTP/1.1" 200 45256 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
123.138.77.50 - - [12/Jul/2020:07:21:39 +0000] "GET /hacked.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:39 +0000] "GET /hacked.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:39 +0000] "GET /fuck.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:39 +0000] "GET /high.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /200879135242729.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /hacker.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /sb.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /default.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /fish.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /history.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /Sdcms_Seach.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /ma.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:40 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /Hacker888.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /admin_detal_add.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /diy3.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /honk.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:40 +0000] "GET /hack2.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:41 +0000] "GET /Pesonal.Asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:41 +0000] "GET /wc.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:41 +0000] "GET /1.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:41 +0000] "GET /liulangren.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:41 +0000] "GET /huiz.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:41 +0000] "GET /qq529601114.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:41 +0000] "GET /201072819315616388.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:41 +0000] "GET /new.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:41 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.138.77.50 - - [12/Jul/2020:07:21:41 +0000] "GET /list.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:42 +0000] "GET /htm.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:42 +0000] "GET /20107281950321634.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:42 +0000] "GET /Admin_Redathengd.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:42 +0000] "GET /index.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:42 +0000] "GET /final.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:42 +0000] "GET /QQ529601114.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:42 +0000] "GET /chinahacker.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:42 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:42 +0000] "GET /Admin_Articlemody.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:42 +0000] "GET /ii1.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:42 +0000] "GET /mda.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /heibats.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /port.php?qq=mm.com HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:43 +0000] "GET /Hacked by" 400 0 "-" "-"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /dst.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /qq529601114.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /index1.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /564684.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /ftb.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /wang.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /201096223137.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /index.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:43 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /7.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /hoclab.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /02142006900.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /indexk.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /xp.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /news.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /windowx.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:43 +0000] "GET /index.jsp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /admin_defroeur.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /muhuo.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /ayst.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /indexx.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /update.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /cz.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /Conews.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /info.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /jjruqin.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /info.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /dama.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /pass.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /zxl.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /iindex.aspx HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /inker.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /new.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:44 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:44 +0000] "GET /default_jp.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /indexs.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /into.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /hacked.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /go.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /love.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /hf2_57.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /jedy.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /zongg/daima.asp?id=66 HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /_.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /musicfeel.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /phpjackal.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /include/downmin.inc.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /axe.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /memberlogin.inc.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:45 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /jia.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /abc.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /web/test.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /Help.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:45 +0000] "GET /zxdker.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /ufohacker.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /fue.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /module/mod_mail.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /jj.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /versions.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /CaoNima.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /cain.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /idn.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /jjruqin.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /hy/hy.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /about.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /hacker.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /images/zencart1.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:46 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /k.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /hx.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:46 +0000] "GET /xmlrpc/sys.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /anzu.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /jing.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /mango.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /game.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /indox.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /include/dig.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /hacksen.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /indox.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /fish.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /admins/diy.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /indeox.shtml HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /sbhelen.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /zencart.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /sky.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /gh.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /php.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /read_write/write.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /xiaoyao.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /job.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:47 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /jkd.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /jssb.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /AdminSE.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:47 +0000] "GET /icef4sh.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /beijing2008.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /jkd.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /1017.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /yll.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /ftp.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /uploadsafa.inc.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /jm.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /Mr.hubbi.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /junior.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /zero.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
84.202.100.14 - - [12/Jul/2020:07:21:48 +0000] "GET /hotcrafthobby/wp-admin/site-health.php HTTP/1.1" 500 4247 "https://clients.azinity.com/hotcrafthobby/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /52hacker.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:48 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /js-yy.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /200881317640594.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /junior.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:48 +0000] "GET /hackway.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /fdg.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /plus/guestbook/default.inc.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /kai.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:49 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /gddff.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /include/downmin.inc.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /windis.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /av.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /data/cache/show.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /loin.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
84.202.100.14 - - [12/Jul/2020:07:21:49 +0000] "GET /favicon.ico HTTP/1.1" 403 4301 "https://clients.azinity.com/hotcrafthobby/wp-admin/site-health.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36"
123.139.42.19 - - [12/Jul/2020:07:21:49 +0000] "GET /safe86.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /myup.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /net.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /admin/Default.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /king.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /NewsType.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /dsf.jsp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /postocer.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:50 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /madman.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /myung.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /juhua.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /xxoo.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /kest.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /christ.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /hc.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /xiaozi.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /dhthacker.com.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /20080812013835393.jpg HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:50 +0000] "GET /xenon.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
34.75.77.246 - - [12/Jul/2020:07:21:51 +0000] "GET /comments/feed/ HTTP/1.0" 500 541 "-" "ZoominfoBot (zoominfobot at zoominfo dot com)"
::1 - - [12/Jul/2020:07:21:51 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /xsd.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /town.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /52.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /20085160619797.cer HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /kuang.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /S.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /kim.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /kk.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /fuck-china.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /jiaoliu.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /kangzai.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /article.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /zongg/daima.asp?id=65 HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:52 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /bubai.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:52 +0000] "GET /kim.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /kk.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /l0rd.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /ChuMeng.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /AnonGuy.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /2008.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /gui.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /kz.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /xiaofeng.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /tvv.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /admin3.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /hoss.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /albums/userpics/robots.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /winSec.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:53 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:53 +0000] "GET /bin.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:54 +0000] "GET /sd.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:54 +0000] "GET /jedy.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:54 +0000] "GET /calendar/calendar.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:54 +0000] "GET /752.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:54 +0000] "GET /UpFile/2.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:54 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:54 +0000] "GET /root.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /2008-kof97.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /JackRiderr.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /alun.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /123.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /201033137326.cer HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /liang.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /hc.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /link.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /201033073008.cer HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /icp4.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /123.ASP HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /xiaoming.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /enusered1itpwd.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /notify.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /liumin.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /200883111832973.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:55 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /lhsq.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:55 +0000] "GET /hacker.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /aa.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /moying.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /1.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /lndex.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /new.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /lisheng.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /Ali.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /hong.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /ufohacker.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /DC_Sybase.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /gl.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /jedy1.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:56 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:56 +0000] "GET /help.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /AR.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /log0.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /ouran.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /ya.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /xxoo.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /xiaohuai.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /login.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /long.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /ccs.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /heiye.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /Index.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /1ndex.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /logo.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:57 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /hacker.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:57 +0000] "GET /qq545235297.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:17 +0000] "GET /up.asp HTTP/1.1" 404 14461 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:58 +0000] "GET /by.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:58 +0000] "GET /haha.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:58 +0000] "GET /ax.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:58 +0000] "GET /downs.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:58 +0000] "GET /love.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:58 +0000] "GET /laibaobuluo.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:58 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:58 +0000] "GET /201083114212730.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:58 +0000] "GET /love.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /Ir.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /admin_login.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /1.aspx HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /2008-kof97.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /201083102230689.asa HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /robots.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /forkert.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /xy.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /lopian.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /vip.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /db.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /m1n6.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /201082517509861.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /test.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /hana.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /youyue.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /make.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /Diispostmaster.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /main.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /youc.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:21:59 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /ksh.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:21:59 +0000] "GET /svhost.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /QQ545235297.TXT HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /css.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /uppic.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /loveyun.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /arrayfunc.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /ajiu.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /hacker-kof97.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /aq.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /newfwse.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /CaoNima.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /adminaini.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /map_api_snippet.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /kew.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /ql.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /karron.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /blackdos.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /xiaobai.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:00 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /qing.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /xiaoyan.asp HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /jungle.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /hitler.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /nima.html HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /r.php HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /2009624162439.cer HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:00 +0000] "GET /liun.htm HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:15 +0000] "GET /aab.asp HTTP/1.1" 404 20564 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.138.77.50 - - [12/Jul/2020:07:21:16 +0000] "GET /aaa.htm HTTP/1.1" 404 20564 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:01 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:01 +0000] "GET /2.cer HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:01 +0000] "GET /965245.TXT HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:01 +0000] "GET /md6.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:01 +0000] "GET /20101109023120571.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:02 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:01 +0000] "GET /webshell886.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:01 +0000] "GET /5.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:02 +0000] "GET /ze0r.asa HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:02 +0000] "GET /admit.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:03 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:02 +0000] "GET /cmd.asa HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:02 +0000] "GET /mdd.asa HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:02 +0000] "GET /z.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:02 +0000] "GET /wolf.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:04 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:02 +0000] "GET /sec.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /include/updateXmlSvr.class.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /ckfinder/userfiles/files/robots.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /mo.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /xiao.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /qq1007474327.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /isosky.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /m_crll.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /cug.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /m_crll.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:03 +0000] "GET /majun.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /hsa.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /robors.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /455812008826163656.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /kurd.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /move.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /qzhk.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /aqgz15.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /mood.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:04 +0000] "GET /cao.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /index1.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /music.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /201083103230414.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /down2.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /muyu.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /wang.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /plus/api.inc.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /honker.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /file.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /hs.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /links/888.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /hack37.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /css.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /hack.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /file.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /loveying.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:06 +0000] "GET /uploadfaceok.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:06 +0000] "GET /right.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:05 +0000] "GET /top.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:06 +0000] "GET /20105236317249.asa HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:12 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:06 +0000] "GET /myccl.asa HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:06 +0000] "GET /myup1.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:13 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:06 +0000] "GET /zhan.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:07 +0000] "GET /national_v3_070.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:07 +0000] "GET /baozi.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:07 +0000] "GET /byg.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:07 +0000] "GET /kill.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:07 +0000] "GET /links.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:07 +0000] "GET /c99.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:07 +0000] "GET /robots.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:07 +0000] "GET /miao.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:08 +0000] "GET /TURKBEY.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:08 +0000] "GET /2010722110920.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:08 +0000] "GET /backup/config.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:15 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:09 +0000] "GET /area.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:08 +0000] "GET /2008824232134387.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:08 +0000] "GET /ty.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:09 +0000] "GET /Dreams.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:09 +0000] "GET /nd.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:09 +0000] "GET /300.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:08 +0000] "GET /xt.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:16 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:09 +0000] "GET /Doom.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:09 +0000] "GET /2011.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:10 +0000] "GET /yanshen.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:10 +0000] "GET /newfile.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:10 +0000] "GET /jia.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:10 +0000] "GET /index.php HTTP/1.1" 301 264 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:10 +0000] "GET /110.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:10 +0000] "GET /xm.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:11 +0000] "GET /logo.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:17 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:10 +0000] "GET /cn.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:11 +0000] "GET /cn.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:18 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:11 +0000] "GET /errors.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:11 +0000] "GET /newsfile.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:12 +0000] "GET /nhs.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:12 +0000] "GET /gap.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:12 +0000] "GET /ff0000.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:12 +0000] "GET /gfy.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:12 +0000] "GET /0cmd.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /anti-microsoft.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:12 +0000] "GET /model/templucg.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /sempak.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /mimi.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /incstion.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:19 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /i.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /vnc.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /k5.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /anti-ms.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /DaoMing.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /xj.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:13 +0000] "GET /caihua.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:14 +0000] "GET /aL_Pars.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:14 +0000] "GET /order.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:14 +0000] "GET /nohack.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:14 +0000] "GET /yy.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:14 +0000] "GET /fengyu.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:14 +0000] "GET /data.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:15 +0000] "GET /200882417252964.asa HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
::1 - - [12/Jul/2020:07:22:20 +0000] "OPTIONS * HTTP/1.0" 200 152 "-" "Apache/2.4.43 (Ubuntu) OpenSSL/1.1.1g (internal dummy connection)"
123.139.42.19 - - [12/Jul/2020:07:22:16 +0000] "GET /STQ.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:16 +0000] "GET /Nilux.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:16 +0000] "GET /phpspy2010.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:16 +0000] "GET /admin/king.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:16 +0000] "GET /admin/Databackup/7.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:16 +0000] "GET /news.asp HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:17 +0000] "GET /at200882413104324704.txt HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:16 +0000] "GET /order.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:16 +0000] "GET /ynxw0.htm HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:17 +0000] "GET /lz1.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:17 +0000] "GET /solo.html HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"
123.139.42.19 - - [12/Jul/2020:07:22:20 +0000] "GET /!.php HTTP/1.1" 404 22853 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"

Hi @Neo,

Below are two lists of malicious IPs taken from two different time frames when the CPU load spiked. The IPs are different every time. Any ideas will be highly appreciated.

BR,
Tom

995    222.79.50.74    China
837    110.167.93.145    China
772    124.235.138.14    China
722    223.166.74.9    China
682    113.128.105.94    China
628    27.211.56.183    China
556    1.30.28.77    China
549    222.94.212.104    China
543    58.244.10.241    China
445    222.94.195.46    China
432    121.57.12.85    China
361    121.57.229.55    China
294    113.128.105.226    China

987    121.57.224.247    China
906    106.45.1.160    China
855    113.128.104.139    China
727    113.200.71.104    China
711    36.5.180.204    China
694    60.208.210.52    China
629    113.57.114.56    China
622    222.94.140.87    China
597    222.74.205.247    China
526    219.143.174.114    China
421    220.175.61.238    China
407    123.139.42.19    China
401    123.179.7.121    China
350    58.19.92.17    China
338    36.47.163.62    China
302    123.138.77.50    China
277    1.80.145.196    China

Hi @tomjansen

My thoughts are as follows:

You should not only examine IP addresses and countries; but you should examine other details should as User Agent strings, page views per minute (or second), etc.

IP address and geoip information is good; but it is not complete.

On the other hand, you could configure your web server to block all traffic from China if you wanted to :slight_smile:

I have code on web apps which will look at the load of the server, and if the load average goes above some threshold, I start blocking all bots from counties like China.

However, I also have code which classifies web activity as "bot or not". Your list of IP addresses and country is a good start, but since you are not classifying traffic as "bot or not" and you are not recording User Agent strings, it is only a partial picture.

Having said that, if you don't have business in China and don't care about Chinese visitors, you could block all traffic from China and "be done with it"; that is up to your "business model", and not for others to determine for you.

1 Like

Hi @Neo,

Thank you so much for sharing your thoughts with us. But how did you tell if a request is a bot in the first place? Take the following request sent to our droplet yesterday as an example. Any idea?

BR,
Tom

123.138.77.50 - - [12/Jul/2020:07:21:33 +0000] "GET /fuck.txt HTTP/1.1" 500 2953 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1"