Trueforce Threat Report
08 Jul 2022
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
Maykson
08 Jul 2022
157.245.15.155 - - [08/Jul/2022:11:09:14 -0300] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 433 ... show more 157.245.15.155 - - [08/Jul/2022:11:09:14 -0300] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 433 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
... show less
Exploited Host
Web App Attack
tradenet
08 Jul 2022
157.245.15.155 - - [08/Jul/2022:03:03:32 -0500] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5. ... show more 157.245.15.155 - - [08/Jul/2022:03:03:32 -0500] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.15.155 - - [08/Jul/2022:03:03:33 -0500] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.15.155 - - [08/Jul/2022:03:03:33 -0500] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.15.155 - - [08/Jul/2022:03:03:34 -0500] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.15.155 - - [08/Jul/2022:03:03:34 -0500] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) C
... show less
Bad Web Bot
Web App Attack
Hirte
07 Jul 2022
ENG: Web Attack GET //wp-includes/wlwmanifest.xml
Web Spam
Hacking
Bad Web Bot
Web App Attack
Mihr
07 Jul 2022
Wordpress vulnerability scanning: "/cms/wp-includes/wlwmanifest.xml"
Web App Attack
Hirte
07 Jul 2022
C1: Web Attack GET /wp-includes/wlwmanifest.xml
Web Spam
Hacking
Bad Web Bot
Web App Attack
ghostwarriors
07 Jul 2022
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
eminovic.ba
07 Jul 2022
Wordpress attack
...
Hacking
Brute-Force
Web App Attack
Danse
07 Jul 2022
(wordpress) Failed wordpress login from 157.245.15.155 (US/United States/ubuntu.gz-s-4vcpu-8gb-intel ... show more (wordpress) Failed wordpress login from 157.245.15.155 (US/United States/ubuntu.gz-s-4vcpu-8gb-intel-nyc3-01): (CF_ENABLE) show less
Brute-Force
MarkGGN
06 Jul 2022
Webexploits. 157.245.15.155 - - [06/Jul/2022:20:21:39 +0200] "GET //wp-includes/wlwmanifest.xml HTTP ... show more Webexploits. 157.245.15.155 - - [06/Jul/2022:20:21:39 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 200 1045 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.15.155 - - [06/Jul/2022:20:21:40 +0200] "GET //wp-json/wp/v2/users/ HTTP/1.1" 200 1142 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" show less
Brute-Force
Bad Web Bot
Web App Attack
Staging
06 Jul 2022
A few hundreds attacks against Wordpress
Hacking
SQL Injection
Brute-Force
Web App Attack
smithclass.net
06 Jul 2022
Jul 6 12:03:35 gravy wordpress(smithclass.net)[1003304]: XML-RPC authentication attempt for unknown ... show more Jul 6 12:03:35 gravy wordpress(smithclass.net)[1003304]: XML-RPC authentication attempt for unknown user gsmithsewanee-edu from 157.245.15.155
... show less
Hacking
Brute-Force
applemooz
06 Jul 2022
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
Major Hostility
06 Jul 2022
"GET /?author=2 HTTP/1.1" 404
"POST /xmlrpc.php HTTP/1.1" 403
Web App Attack
plzenskypruvodce.cz
06 Jul 2022
[Wed Jul 06 06:12:35.650727 2022] [access_compat:error] [pid 1763045:tid 140051954521856] [client 15 ... show more [Wed Jul 06 06:12:35.650727 2022] [access_compat:error] [pid 1763045:tid 140051954521856] [client 157.245.15.155:57409] AH01797: client denied by server configuration: /var/www/lubosluka.com/www/xmlrpc.php
[Wed Jul 06 06:12:35.752944 2022] [access_compat:error] [pid 1763045:tid 140051937736448] [client 157.245.15.155:57409] AH01797: client denied by server configuration: /var/www/lubosluka.com/www/xmlrpc.php
... show less
Web App Attack