I review my sites log file just about every week. In the log I often find a string of 404 errors like this listing below. These 404’s errors are from a hacker poking around my hosting account. They hit the account 3-4 times a minute, cycling their IP for each hit. In this case they were looking for old copies of the site that may not be maintained and secure. Once they find an old copy, they will poke deeper looking for vulnerable code so they can break in.
Do not keep out-of-date or unmaintained copies of your site online. Hackers will probe the old site for known security vulnerabilities and break in. Once in your account they may be able to access the live version of your site.
If you are not maintaining your CMS, and securing your website on a regular bases, sign up for one of my CMS Maintenance Plans or hire a professional you trust to maintain your site for you.
Time | IP | URL | IP’s Location |
@09:38 | 124.158.179.23 | mysite.com/blog/ | Desa Puspasari, Indonesia |
@09:38 | 14.241.228.101 | mysite.com/wordpress/ | Hanoi, Vietnam |
@09:38 | 124.43.16.56 | mysite.com/wp/ | Colombo, Sri Lanka |
@09:39 | 83.130.89.60 | mysite.com/news/ | Nes Harim, Israel |
@09:39 | 45.70.159.211 | mysite.com/site/ | Matipó, Brazil |
@09:39 | 147.30.251.199 | mysite.com/blogs/ | Nur-Sultan, Kazakhstan |
@09:40 | 103.81.93.158 | mysite.com/home/ | Tirupati, India |
@09:40 | 171.227.11.202 | mysite.com/home/ | Hanoi, Vietnam |
@09:40 | 183.83.210.5 | mysite.com/home/ | Pitampura, India |
@09:41 | 106.201.155.106 | mysite.com/cms/ | … and on and on |
@09:41 | 154.68.5.98 | mysite.com/main/ | |
@09:41 | 2.135.251.41 | mysite.com/articles/ | |
@09:41 | 200.223.31.133 | mysite.com/blog1/ | |
@09:42 | 177.36.162.184 | mysite.com/en/ | |
@09:42 | 115.134.66.174 | mysite.com/new/ | |
@09:42 | 37.104.17.42 | mysite.com/content/ | |
@09:42 | 154.41.5.224 | mysite.com/web/ | |
@09:43 | 117.0.109.184 | mysite.com/weblog/ | |
@09:43 | 27.33.230.232 | mysite.com/journal/ | |
@09:43 | 131.0.85.247 | mysite.com/journal/ | |
@09:44 | 213.149.61.52 | mysite.com/blog2/ | |
@09:44 | 213.194.180.176 | mysite.com/newsite/ | |
@09:44 | 189.144.223.73 | mysite.com/wpblog/ | |
@09:45 | 42.114.242.0 | mysite.com/test/ | |
@09:45 | 45.183.243.45 | mysite.com/dev/ | |
@09:45 | 105.108.113.147 | mysite.com/website/ | |
@09:45 | 116.101.237.90 | mysite.com/info/ | |
@09:45 | 27.2.146.233 | mysite.com/myblog/ | |
@09:46 | 36.71.136.248 | mysite.com/wordpress1/ | |
@09:46 | 88.24.182.100 | mysite.com/wordpress1/ | |
@09:46 | 171.251.234.52 | mysite.com/index/ | |
@09:47 | 189.41.7.238 | mysite.com/community/ | |
@09:47 | 161.0.154.227 | mysite.com/portfolio/ | |
@09:47 | 116.108.233.54 | mysite.com/press/ | |
@09:48 | 187.64.66.34 | mysite.com/pages/ | |
@09:48 | 42.114.108.189 | mysite.com/w/ | |
@09:48 | 37.165.72.163 | mysite.com/word/ | |
@09:48 | 49.228.48.215 | mysite.com/core/ | |
@09:48 | 86.140.144.113 | mysite.com/b/ | |
@09:48 | 188.119.11.157 | mysite.com/magazine/ | |
@09:49 | 43.228.131.115 | mysite.com/wpress/ | |
@09:49 | 210.187.199.11 | mysite.com/1/ | |
@09:49 | 88.230.141.196 | mysite.com/wp2/ | |
@09:50 | 125.164.156.84 | mysite.com/2013/ | |
@09:51 | 189.82.45.138 | mysite.com/newsletter/ | |
@09:51 | 202.83.173.148 | mysite.com/updates/ | |
@09:52 | 79.129.54.7 | mysite.com/stating/ | |
@09:52 | 117.207.180.197 | mysite.com/2012/ | |
@09:52 | 27.5.105.249 | mysite.com/2014/ | |
@09:53 | 14.182.233.94 | mysite.com/2015/ | |
@09:53 | 14.231.212.211 | mysite.com/2015/ | |
@09:53 | 202.70.138.222 | mysite.com/2016/ | |
@09:53 | 187.189.217.246 | mysite.com/2017/ | |
@09:54 | 117.211.27.188 | mysite.com/2018/ | |
@09:54 | 115.135.232.185 | mysite.com/2019/ | |
@09:54 | 113.162.38.84 | mysite.com/2020/ | |
@09:54 | 103.249.233.38 | mysite.com/v1/ | |
@09:55 | 103.195.2.8 | mysite.com/whatsnew/ | |
@09:55 | 14.171.238.48 | mysite.com/portal/ | |
@09:55 | 80.87.212.26 | mysite.com/old/ | |
@09:55 | 197.247.67.141 | mysite.com/beta/ | |
@09:56 | 84.17.43.140 | mysite.com/beta/ | |
@09:56 | 113.53.35.138 | mysite.com/live/ | |
@09:56 | 103.39.8.20 | mysite.com/reviews/ | |
@09:56 | 210.212.242.75 | mysite.com/english/ | |
@09:57 | 88.81.236.222 | mysite.com/wp1/ | |
@09:57 | 78.165.12.14 | mysite.com/wordpress2/ | |
@09:57 | 171.250.92.222 | mysite.com/store/ | |
@09:57 | 14.184.65.223 | mysite.com/store/ | |
@09:57 | 49.205.251.230 | mysite.com/eng/ | |
@09:58 | 85.154.69.165 | mysite.com/resources/ | |
@09:58 | 14.207.182.4 | mysite.com/newblog/ | |
@09:58 | 219.92.102.204 | mysite.com/welcome/ | Kuala Lumpur, Malaysia |
Pro Tip: Use DB-IP to lookup the location for an IP. Like that last one @9:58 219.92.102.204: https://db-ip.com/219.92.102.204