On Thu, Feb 4, 2021 at 6:07 PM Adam Carter <adamcart...@gmail.com> wrote:
> On Thursday, February 4, 2021, <the...@sys-concept.com> wrote: > >> I'm perplex with this entry in apache log. >> I'm sure it was done by same person as the timing is very sequential and >> same file-name request, but how they were able to lunch an attack from a >> different IP's different geographical locations. >> Can they spoof an IP? >> >> > Probably just different instances of the same bot scanning for > vulnerabilities. I imagine you will keep seeing that log from many > different ips > FWIW i'm seeing the same traffic. Here's some numbers; $ zgrep -ic wlwmanifest.xml access.log* access.log:16 access.log-20210110.gz:0 access.log-20210117.gz:0 access.log-20210124.gz:34 access.log-20210131.gz:0