Unusual Log File Being Generated
-
I noticed I started getting E-Mails from iThemes Security about a File Change in error_log.
On further investigation this is generating this on a frequent basis:
[25-Nov-2018 21:03:44 UTC] PHP Warning: file_put_contents(/var/www/clients/client74/web304/web/wp-content/uploads/ithemes-security/logs/event-log-adam-zook-consulting-pPrxqCmj6GUP8p1C6NsegS1bjrlpGx.log): failed to open stream: No such file or directory in /home/actualdomainid/public_html/wp-content/plugins/better-wp-security/core/lib/log.php on line 176I replaced my company name with actualdomainid in this error. /var/www/clients/client74/web304/ was the location my site was on with my previous hosting provider though and I do not have a clue who adam-zook-consulting is and doing a google search has yielded no results either.
Sure enough checking /public_html/wp-content/uploads/ithemes-security/logs there is a file over 10MB called event-log-adam-zook-consulting-pPrxqCmj6GUP8p1C6NsegS1bjrlpGx.log.1 and a newer one that is 6MB called event-log-adam-zook-consulting-pPrxqCmj6GUP8p1C6NsegS1bjrlpGx.log
There is a lot in that file and my domain name is mentioned a lot. I have removed my domain name below:
"REDIRECT_REDIRECT_REDIRECT_REMOTE_PORT"";s:5:""36096"";s:48:""REDIRECT_REDIRECT_REDIRECT_REDIRECT_QUERY_STRING"";s:47:""doing_wp_cron=1527004732.0275049209594726562500"";s:39:""REDIRECT_REDIRECT_REDIRECT_REDIRECT_URL"";s:12:""/wp-cron.php"";s:44:""REDIRECT_REDIRECT_REDIRECT_GATEWAY_INTERFACE"";s:7:""CGI/1.1"";s:42:""REDIRECT_REDIRECT_REDIRECT_SERVER_PROTOCOL"";s:8:""HTTP/1.1"";s:41:""REDIRECT_REDIRECT_REDIRECT_REQUEST_METHOD"";s:4:""POST"";s:39:""REDIRECT_REDIRECT_REDIRECT_QUERY_STRING"";s:47:""doing_wp_cron=1527004732.0275049209594726562500"";s:38:""REDIRECT_REDIRECT_REDIRECT_REQUEST_URI"";s:60:""/wp-cron.php?doing_wp_cron=1527004732.0275049209594726562500"";s:38:""REDIRECT_REDIRECT_REDIRECT_SCRIPT_NAME"";s:10:""/php5-fcgi"";s:36:""REDIRECT_REDIRECT_REDIRECT_PATH_INFO"";s:12:""/wp-cron.php"";s:42:""REDIRECT_REDIRECT_REDIRECT_PATH_TRANSLATED"";s:48:""/var/www/clients/client74/web304/web/wp-cron.php"";s:33:""REDIRECT_REDIRECT_REDIRECT_STATUS"";s:3:""103"";s:28:""REDIRECT_REDIRECT_SCRIPT_URL"";s:12:""/wp-cron.php"";s:28:""REDIRECT_REDIRECT_SCRIPT_URI"";s:38:""http://www.MYDOMAINNAME.co.uk/wp-cron.php"";s:24:""REDIRECT_REDIRECT_STATUS"";s:3:""103"";s:19:""REDIRECT_SCRIPT_URL"";s:12:""/wp-cron.php"";s:19:""REDIRECT_SCRIPT_URI"";s:38:""http://www.MYDOMAINNAME.co.uk/wp-cron.php"";s:16:""REDIRECT_HANDLER"";s:9:""php5-fcgi"";s:15:""REDIRECT_STATUS"";s:3:""103"";s:10:""SCRIPT_URL"";s:12:""/wp-cron.php"";s:10:""SCRIPT_URI"";s:38:""http://www.MYDOMAINNAME.co.uk/wp-cron.php"";s:15:""HTTP_USER_AGENT"";s:43:""WordPress/4.9.6; http://www.MYDOMAINNAME.co.uk"";s:9:""HTTP_HOST"";s:19:""www.MYDOMAINNAME.co.uk"";s:11:""HTTP_ACCEPT"";s:3:""*/*"";s:20:""HTTP_ACCEPT_ENCODING"";s:13:""deflate, gzip"";s:12:""HTTP_REFERER"";s:86:""http://www.MYDOMAINNAME.co.uk/wp-cron.php?doing_wp_cron=1527004732.0275049209594726562500"";s:15:""HTTP_CONNECTION"";s:5:""close"";s:14:""CONTENT_LENGTH"";s:1:""0"";s:12:""CONTENT_TYPE"";s:33:""application/x-www-form-urlencoded"";s:16:""SERVER_SIGNATURE"";s:0:"""";s:11:""SERVER_NAME"";s:19:""www.MYDOMAINNAME.co.uk"";s:11:""SERVER_ADDR"";s:13:""5.153.225.102"";s:11:""SERVER_PORT"";s:2:""80"";s:11:""REMOTE_ADDR"";s:13:""5.153.225.102"";s:13:""DOCUMENT_ROOT"";s:36:""/var/www/clients/client74/web304/web"";s:12:""SERVER_ADMIN"";s:25:""[email protected]"";s:15:""SCRIPT_FILENAME"";s:46:""/var/www/clients/client74/web304/web/index.php"";s:11:""REMOTE_PORT"";s:5:""36096"";s:12:""REDIRECT_URL"";s:10:""/index.php"";s:17:""GATEWAY_INTERFACE"";s:7:""CGI/1.1"";s:15:""SERVER_PROTOCOL"";s:8:""HTTP/1.1"";s:14:""REQUEST_METHOD"";s:3:""GET"";s:12:""QUERY_STRING"";s:0:"""";s:11:""SCRIPT_NAME"";s:10:""/index.php"";s:20:""ORIG_SCRIPT_FILENAME"";s:71:""/var/www/clients/client74/web304/cgi-bin/php5-fcgi-*-80-It looks like the IP 5.153.225.102 is the old hosting provider.
If anyone can offer any advice it would be appreciated.
The topic ‘Unusual Log File Being Generated’ is closed to new replies.