I have a strange issue where whenever I send out a mailchimp mail campaign. My website then recieves lots of suspicious requests trying to access files. This only appears to be happening when I send a campaign from within MailChimp? My server then hits high CPU and I recieve the following in my php fpm logs:
[12-Sep-2024 14:21:28] WARNING: [pool www] seems busy (you may need to increase pm.start_servers, or pm.min/max_spare_servers), spawning 32 children, there are 0 idle, and 22 total children[12-Sep-2024 14:21:29] WARNING: [pool www] server reached pm.max_children setting (25), consider raising it
My access logs look like:
172.207.171.136 - - [12/Sep/2024:08:44:15 +0000] "GET /wp-includes/blocks/avatar/ HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0"172.207.171.136 - - [12/Sep/2024:08:44:15 +0000] "GET /wp-includes/Requests/src/Exception/Http/ HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"172.207.171.136 - - [12/Sep/2024:08:44:16 +0000] "GET /wp-content/wp-content/patior/ HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"172.207.171.136 - - [12/Sep/2024:08:44:16 +0000] "GET /naujienos/ HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0"172.207.171.136 - - [12/Sep/2024:08:44:17 +0000] "GET /wp-content/fonts/cherry-swash/___security/ HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0"172.207.171.136 - - [12/Sep/2024:08:44:17 +0000] "GET /wp-content/themes/eptonic/functions/jwpanel/scripts/valums_uploader/ HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0"17.241.227.161 - - [12/Sep/2024:08:45:04 +0000] "GET /robots.txt HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"17.241.227.161 - - [12/Sep/2024:08:45:04 +0000] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"17.241.219.178 - - [12/Sep/2024:08:48:05 +0000] "GET /contact HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"17.241.227.34 - - [12/Sep/2024:08:49:43 +0000] "GET / HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"216.244.66.241 - - [12/Sep/2024:08:51:23 +0000] "GET /robots.txt HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; DotBot/1.2; +https://opensiteexplorer.org/dotbot; help@moz.com)"162.142.125.210 - - [12/Sep/2024:08:55:42 +0000] "GET / HTTP/1.1" 444 0 "-" "-"162.142.125.210 - - [12/Sep/2024:08:55:43 +0000] "\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xCF`R\x9D&\xB3\x87\xF6i\x1B4\xD8\x07\x04\x10\xDD\x1D\xBC\x06`f\x08w\xD7D\x08\x857\xC6\xF1\xBA\x9F 27\x02\xE2\xDB0\x8CFx\x22I\x05\x03\xDA\x89P\x85\x81\xFAZ\xFE\xD8\xB8\xC3V\x86\xC3\xC3\x83\xAA\xF6\x05\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0" 400 150 "-" "-"172.212.58.250 - - [12/Sep/2024:08:56:38 +0000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 zgrab/0.x"107.151.150.64 - - [12/Sep/2024:09:00:38 +0000] "GET http://74.63.247.151:9994/proxys HTTP/1.1" 400 650 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.115 Safari/537.36"143.110.222.166 - - [12/Sep/2024:09:00:47 +0000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Mobile/15E148 Safari/604.1"185.191.126.213 - - [12/Sep/2024:09:03:58 +0000] "GET / HTTP/1.1" 444 0 "-" "-"209.222.82.114 - - [12/Sep/2024:09:05:51 +0000] "GET / HTTP/1.1" 301 162 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729)"17.241.75.113 - - [12/Sep/2024:09:10:58 +0000] "GET /robots.txt HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"17.241.75.113 - - [12/Sep/2024:09:10:59 +0000] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"143.255.104.115 - - [12/Sep/2024:09:17:30 +0000] "GET / HTTP/1.1" 444 0 "-" "-"143.255.104.115 - - [12/Sep/2024:09:17:35 +0000] "GET / HTTP/1.1" 444 0 "-" "-"143.255.104.115 - - [12/Sep/2024:09:17:40 +0000] "GET / HTTP/1.1" 444 0 "-" "-"18.133.136.111 - - [12/Sep/2024:09:23:51 +0000] "GET / HTTP/1.1" 301 162 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729)"81.179.163.241 - - [12/Sep/2024:09:27:52 +0000] "GET /wp-content/plugins/gravityforms/images/tick.png HTTP/2.0" 301 162 "-" "Mozilla/4.0 (compatible; ms-office; MSOffice 16)"71.6.134.235 - - [12/Sep/2024:09:34:41 +0000] "\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xE0'\x80g{\x1C\xD5\xBB\xB0\xEA\x03kN\xB4\xD2\xED\x14Q?]\x83\xCB\x18\xBF\x16\xC5WC\xA30\xCE\xD7 \x8B|[\x99\x871\x9F\x92vq\x8B,\x1Em\x9C\x1A\xD8\x1D*\xDA\x1A6\x94\xDE_\xAC'\x83\xA9J\xBE\xE1\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:50 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xEA\xB2\xA4\xBF\xFD\x99\x10,\xD30\xC5\xC9\x91\xAD\xAB\xA1dGi\xCC/\x01\xE8\xFB\xB47\x10\x19X\xFD\xDF\xF3 n\x91\x1B\xE2:\xBB\xF53G\xC08\xF2\x84P\xD7\xB2&\x03\x5C)\xC9\xCF\xAB\x1Dg\x7F\x82e\xB9W\x9F\x04\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:50 +0000] "GET / HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:50 +0000] "GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:50 +0000] "\x0E\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00bbbb0100000001" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:50 +0000] "GET /server-status HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x030\xC2/\x1E\xB9$\x90\xDAt\xF6\xB4\xA2\xA3\xC4C\xFEGp\x9A\x1E\xB8\xB4\x04\xB3^9\xDF\xFE\x93\xEBMb \xB0\xFBi\x87\xF6fd\xA5\x85.p\xA9\xFB\xB9\x1EV[\xFB\xC2\x18\xC2\xEB\x04\xB3\xD0\xC0\xF4\xE0g\x01;\xE8\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /CSS/Miniweb.css HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x1Be\x1C\x95\xDA\xE4\xA5l\xCF\x040Q\xE5\x922P{\xA8\x5CY" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x8F\xDB\xFD3\x0C\xB6.\x8E\xEB\xB70L.\x82U\xBC\xB0\xD33\x92\x05>\xFDi\xD3\xD3\x18\xF2\xCFS\x96\xE4 \xAEE\xA6\x89\x87\x97\xF1X\xA5\x8C\xEAbUO0\xCE7\x9D\x16\xC7\xB5\xAE\xCD\xFD\xBB\xEB\xD6L\xC9F\x1Bc\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /pools/default/buckets HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET / HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /nmaplowercheck1726134947 HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /webui HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /hXSI HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03Q\x99s\x87]n\x1B\xC1a\xCA\x81\xDC\x8A\xF1\xA3.\x11F\x8A\xCAF\xF3B|^=N\x89sE\xCCs 2sB:\xF3~\xB0\xB5\x9C\x94d\xE4\xCB\xF1\x8A(\xC1e|rD\xF4\xC0JC\x12\xF8\x02\x0F\xA3\xBE8\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /Oy1c HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x14L/vi3 ?\xEED\x18\x88wE\x97\xC7\x85\x0F9\x1Ep|\xB0\xB3J\x9B\x097\xA1\xB5y\x8E \xBA\x13\x0C\x8E?p\x1CG\xEA\x9AX\xAD\xE9gB\x22z\xB9HN\xBE\x22Y\x82m\xA0\xFB\x17\xD5\xF9 \x15\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03sd\xBA/\x8A\xC8\xD5\xCB&\xBC\xA3\xD0\x80\xE55\x5C\xA1?\x80fW0\x12\x11 M\x95\xBB\xB0\x94\xB02 \x9D\xFE\x95\xE1" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /Portal0000.htm HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /pools HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /home.pl HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03&^5\xF0\xB8\xB2\xA7J\xAE\x1C\xE2\x1C\x9E\x05n\xB1\x1A\x94e\xD3Km{y\xED\xBF\x1E\x0E\xA1\xAC\x13 \xFD\xFA\x87\x8Fp\xF2\xAD\xF8&\xF5\xCF\xA91\xE8\xE8\x87\x1E\xFC\xCA?\xB3\xE4n%x[h*E\xAD\xC3\xF2\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET / HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xF7B\x0F&\x972\xE7H\xBFQ\xBD+\x05Y\xDF\x83\x8B\xD2\x8F" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x8Dr\xCD\xEA\x1EC\xB2g\xC9\x063\x14zB]\xCD\xA9wB\xA5\x95\x82$\x14\xA36\xE4\xC3\x8Fb\xAF\x91 S\xA7\x15\xE0\x8E\x04Q\xF3\xF0\xABv\xAD\xEC\xB6\x84]m\x96\x91\x98n'a\xBA\x9BUc<\xC88\x8Cu\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /owa/ HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /Portal/Portal.mwsl HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /owa/ HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /docs/cplugError.html/ HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET / HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /HNAP1 HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "POST /sdk HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "GET /user HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:51 +0000] "POST /sdk HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03L\xA7\xBC\xD7\x19\x10K\xB6\xACNE~b\xCE-$\xCF\x9F\x8D|\x9F\x9A\x1C}\xD4.\x04#&\x18;L \xDF\x8E,\x09\x8C\x0B\xB8\xF6 \xF4I\x8C\x88\xF8\xC3\x14\xDC\xFD,$\x1D\x1A\xF52\xAB\xA6_\xC4\xCF\x8B%q\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x96\x1D\x10C\x07\x94lZ%\x9A\x05|;\xBA\xD2\x1A\xB8y\xBF\x05\x04\x16\xE3r\xA4\xBD\xBC_\xEA\xD9\xD6T 2" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "HEAD / HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03LR6\x00\x0BVYry\x09\x86^\x1A\x08\x8A\xA3\xBE\x1A?-9(\x96\x95\x03\xFB\x22Z\x92\x91\x15\xB1 p\xF2\xC5\x9FG" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x9E\xEC<A\xBF\xA9\xD0\xD5\x93\x0B\xB5`\x92>\xFFC\xA2IE\xBC\x10dVs\x98,\xF9>\xCB\x953| \x84\x8D!\xAAz\xF4\x7Ff\x15]s\xA5\xA7\xAD\xD1\xBA\x91\x8F\xB3\xFE|\x82\xC1/\x19\x1B\xFA&\x8E\xB2\xDF\x03\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xA3J\xCF\xF2\x04\xDA[\x06\x1B\x1C\x01\x8E`\x07\xD1\x10\x8F\xA58'jb\xCA|\xD2\xAB\xC0\xFDn\xA7+\x15 \xC9w\xD266 \xF8\xE7\xC4]x\x92\xD9\x842\xB9\x08n\x8F\xE9y\xAF :\xD45\x14uF\x10\xC5C\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "GET /default.asp HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "GET /default.php HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:52 +0000] "GET /main.jhtml HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:53 +0000] "GET /home.jsp HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:53 +0000] "GET / HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:53 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xC5q\xFAx(\xA9p-\xEA<\x80C\xF6\x895\x13\x10\xD4%\xE5\xF0\xF0\x97z7\xD7\xA4O\xA0F\xBE\x05 \xB3c\xCB\xC0/ht\xE4.%\xD4\x07\xA3\x5C\xA5\x88\xF8\x96\x14jw*\xD9\xE2\xAF\x89\x8B\xC9\xFFB\x95F\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:53 +0000] "GET /favicon.ico HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:53 +0000] "GET / HTTP/1.1" 444 0 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:53 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xEBB\x1Ff\x1F\xE7\xCB\xE7$\xE4Z\x9C\x93\xF2!\x87\xE4QoI\x0B\x14R\xE0\xDB9]\xD1d\x8F%V j\x92\xF8\xBD\xAC\x9FzKw\xD1\x961\xAB\xA1]\xFA\xDF=\x8F\x84\xD3\x93_#2G,/\x88\xF5C\x5C\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:53 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x0Bz\xB0B1\x93[\x099\xB0\xAE]\x97\xF4\xA0\xFA)A*\xC3'\x98" 400 150 "-" "-"109.74.204.123 - - [12/Sep/2024:09:55:54 +0000] "GET /robots.txt HTTP/1.1" 400 248 "-" "curl/7.54.0"109.74.204.123 - - [12/Sep/2024:09:55:55 +0000] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xCE\xC2;\xC4\xDD?\xDA\x0C\x9C\xCB\x03\xCD\xDEz\x88*l\xD1f('\x06r6\x9C\xB21[\x1C\xE2\xE5\xD2 \xE7 \xC4*JECJ\x9EH\x8A\xA4'6#\xA4,\xE5\xCDGX_\xE73Jc\x0CR\xF6\xE4\xDB\x8C\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0'\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0" 400 150 "-" "-"
I'm using free tier cloudflare, and set up to block bots, but I'm thinking there must be something I need to do on my server to be able to help resolve the error.
Unfortunetly this is causing me problems, as customers are then using the links in my mail but cannot access the site since the server CPU is at 100%.
Any help in fixing this, or advice on how I can secure my website, would be much appreciated.
Note, that the IP's change eachtime, I keep trying to add firewall rule to block IP but they it just happens again?