Check the IP's on https://www.abuseipdb.com/ or similar, or do a
hostname and whois lookup

The 3 IP's I checked all come from the same organisation/location
(secureserver.net in the US) ...

BillK


On 4/2/21 3:07 pm, Adam Carter wrote:
> On Thursday, February 4, 2021, <[email protected]
> <mailto:[email protected]>> wrote:
>
>     I'm perplex with this entry in apache log. 
>     I'm sure it was done by same person as the timing is very
>     sequential and same file-name request, but how they were able to
>     lunch an attack from a different IP's different geographical
>     locations.
>     Can they spoof an IP?
>
>
> Probably just different instances of the same bot scanning for
> vulnerabilities. I imagine you will keep seeing that log from many
> different ips 
>
>  
>
>     173.201.196.206 - - [03/Feb/2021:19:17:47 -0700] "GET
>     /wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     195.70.43.234 - - [03/Feb/2021:19:18:24 -0700] "GET
>     /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     198.38.92.110 - - [03/Feb/2021:19:21:18 -0700] "GET
>     /new/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     50.62.208.141 - - [03/Feb/2021:19:21:20 -0700] "GET
>     /en/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     64.62.206.242 - - [03/Feb/2021:19:21:34 -0700] "GET
>     /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     184.168.46.171 - - [03/Feb/2021:19:22:11 -0700] "GET
>     /home/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     50.63.196.23 - - [03/Feb/2021:19:23:41 -0700] "GET
>     /www/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     203.205.21.159 - - [03/Feb/2021:19:23:57 -0700] "GET
>     /staging/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     66.113.226.191 - - [03/Feb/2021:19:25:42 -0700] "GET
>     /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     148.72.232.107 - - [03/Feb/2021:19:26:06 -0700] "GET
>     /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     35.208.134.190 - - [03/Feb/2021:19:26:22 -0700] "GET
>     /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     160.153.153.30 - - [03/Feb/2021:19:26:50 -0700] "GET
>     /main/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     192.241.230.24 - - [03/Feb/2021:19:27:50 -0700] "GET
>     /v2/wp-includes/wlwmanifest.xml HTTP/1.1" 403 199
>     66.113.221.43 - - [03/Feb/2021:19:28:37 -0700] "GET
>     /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     2.50.180.72 - - [03/Feb/2021:19:28:48 -0700] "GET
>     /portal/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     104.236.82.97 - - [03/Feb/2021:19:29:39 -0700] "GET
>     /2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     50.63.197.91 - - [03/Feb/2021:19:30:46 -0700] "GET
>     /1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     103.27.61.222 - - [03/Feb/2021:19:30:57 -0700] "GET
>     /store/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     184.168.152.18 - - [03/Feb/2021:19:31:14 -0700] "GET
>     /wp2/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>     184.168.193.129 - - [03/Feb/2021:19:31:24 -0700] "GET
>     /blogs/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
>

Reply via email to