Yeah, and how to protect from this (D)DoS attempts? Do you have any idea or anything? I want to disapear these all unreal visits.I mean this is pretty much a (D)DoS attempt. He's either rotating proxies and User-Agent headers or using a small botnet. The reason for the search queries in that case would be because it's often a really easy way to spike memory and CPU usage because few people running a WP site cache search results or use rate limiting.
I would temporarily disable search (or switch to Google search). Also look at the logs right before it happened. I suspect the origin might be 141.101.98.14 because it's a cloudflare IP and it used the default Go HTTP client User-Agent https://golang.org/src/net/http/request.go#L458.
How to setup this on cPanel / Wordpress?Your first problem is you not installing the cloudflare "restore ip" addon..
https://support.cloudflare.com/hc/en-us/sections/200805497-Restoring-Visitor-IPs
All ip's in screenshot are Cloudflare proxy ip's, which prevent you from finding the real culprit.
The user-agents look like bot rotators, using outdated browser strings, install restore ip mod, and check your access logs, for a couple of them to spot patterns.
Reach 1000's of webmasters, hosts & affiliates. Banner & sponsored-thread slots available.
Contact us