1 |
On Thu, Feb 4, 2021 at 6:07 PM Adam Carter <adamcarter3@×××××.com> wrote: |
2 |
|
3 |
> On Thursday, February 4, 2021, <thelma@×××××××××××.com> wrote: |
4 |
> |
5 |
>> I'm perplex with this entry in apache log. |
6 |
>> I'm sure it was done by same person as the timing is very sequential and |
7 |
>> same file-name request, but how they were able to lunch an attack from a |
8 |
>> different IP's different geographical locations. |
9 |
>> Can they spoof an IP? |
10 |
>> |
11 |
>> |
12 |
> Probably just different instances of the same bot scanning for |
13 |
> vulnerabilities. I imagine you will keep seeing that log from many |
14 |
> different ips |
15 |
> |
16 |
|
17 |
FWIW i'm seeing the same traffic. Here's some numbers; |
18 |
|
19 |
$ zgrep -ic wlwmanifest.xml access.log* |
20 |
access.log:16 |
21 |
access.log-20210110.gz:0 |
22 |
access.log-20210117.gz:0 |
23 |
access.log-20210124.gz:34 |
24 |
access.log-20210131.gz:0 |