Gentoo Archives: gentoo-user

From: William Kenworthy <billk@×××××××××.au>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] spam - different IP's
Date: Thu, 04 Feb 2021 07:19:04
Message-Id: 273d9af0-c8d9-b8e5-abbd-f3be273e3286@iinet.net.au
In Reply to: Re: [gentoo-user] spam - different IP's by Adam Carter
1 Check the IP's on https://www.abuseipdb.com/ or similar, or do a
2 hostname and whois lookup
3
4 The 3 IP's I checked all come from the same organisation/location
5 (secureserver.net in the US) ...
6
7 BillK
8
9
10 On 4/2/21 3:07 pm, Adam Carter wrote:
11 > On Thursday, February 4, 2021, <thelma@×××××××××××.com
12 > <mailto:thelma@×××××××××××.com>> wrote:
13 >
14 > I'm perplex with this entry in apache log. 
15 > I'm sure it was done by same person as the timing is very
16 > sequential and same file-name request, but how they were able to
17 > lunch an attack from a different IP's different geographical
18 > locations.
19 > Can they spoof an IP?
20 >
21 >
22 > Probably just different instances of the same bot scanning for
23 > vulnerabilities. I imagine you will keep seeing that log from many
24 > different ips 
25 >
26 >  
27 >
28 > 173.201.196.206 - - [03/Feb/2021:19:17:47 -0700] "GET
29 > /wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
30 > 195.70.43.234 - - [03/Feb/2021:19:18:24 -0700] "GET
31 > /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
32 > 198.38.92.110 - - [03/Feb/2021:19:21:18 -0700] "GET
33 > /new/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
34 > 50.62.208.141 - - [03/Feb/2021:19:21:20 -0700] "GET
35 > /en/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
36 > 64.62.206.242 - - [03/Feb/2021:19:21:34 -0700] "GET
37 > /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
38 > 184.168.46.171 - - [03/Feb/2021:19:22:11 -0700] "GET
39 > /home/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
40 > 50.63.196.23 - - [03/Feb/2021:19:23:41 -0700] "GET
41 > /www/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
42 > 203.205.21.159 - - [03/Feb/2021:19:23:57 -0700] "GET
43 > /staging/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
44 > 66.113.226.191 - - [03/Feb/2021:19:25:42 -0700] "GET
45 > /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
46 > 148.72.232.107 - - [03/Feb/2021:19:26:06 -0700] "GET
47 > /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
48 > 35.208.134.190 - - [03/Feb/2021:19:26:22 -0700] "GET
49 > /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
50 > 160.153.153.30 - - [03/Feb/2021:19:26:50 -0700] "GET
51 > /main/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
52 > 192.241.230.24 - - [03/Feb/2021:19:27:50 -0700] "GET
53 > /v2/wp-includes/wlwmanifest.xml HTTP/1.1" 403 199
54 > 66.113.221.43 - - [03/Feb/2021:19:28:37 -0700] "GET
55 > /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
56 > 2.50.180.72 - - [03/Feb/2021:19:28:48 -0700] "GET
57 > /portal/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
58 > 104.236.82.97 - - [03/Feb/2021:19:29:39 -0700] "GET
59 > /2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
60 > 50.63.197.91 - - [03/Feb/2021:19:30:46 -0700] "GET
61 > /1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
62 > 103.27.61.222 - - [03/Feb/2021:19:30:57 -0700] "GET
63 > /store/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
64 > 184.168.152.18 - - [03/Feb/2021:19:31:14 -0700] "GET
65 > /wp2/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
66 > 184.168.193.129 - - [03/Feb/2021:19:31:24 -0700] "GET
67 > /blogs/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196
68 >