Ross Wheatley
08 Jul 2022
GET /xmlrpc.php?rsd HTTP/1.1 404 491 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ... show more GET /xmlrpc.php?rsd HTTP/1.1 404 491 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36 show less
Brute-Force
Web App Attack
DumaNet
05 Jul 2022
WordPress (CMS) attack attempts.
Date: 2022 Jul 02. 18:39:54
Source IP: 20.111.48.39<b ... show more WordPress (CMS) attack attempts.
Date: 2022 Jul 02. 18:39:54
Source IP: 20.111.48.39
Portion of the log(s):
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //sito/wp-includes/wlwmanifest.xml HTTP/1.1" 404 571 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //cms/wp-includes/wlwmanifest.xml
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //site/wp-includes/wlwmanifest.xml
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //wp2/wp-includes/wlwmanifest.xml
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //test/wp-includes/wlwmanifest.xml
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //wp1/wp-includes/wlwmanifest.xml
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //news/wp-includes/wlwmanifest.xml
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //wp/wp-includes/wlwmanifest.xml
20.111.48.39 - [02/Jul/2022:18:39:53 +0200] "GET //website/wp-includes/wlwmanifest.xml show less
Web App Attack
blueSh4rk
03 Jul 2022
Directory scanning
Bad Web Bot
Web App Attack
Vaction
02 Jul 2022
20.111.48.39 - - [02/Jul/2022:16:59:02 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "- ... show more 20.111.48.39 - - [02/Jul/2022:16:59:02 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
20.111.48.39 - - [02/Jul/2022:16:59:02 +0200] "GET /xmlrpc.php?rsd HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
20.111.48.39 - - [02/Jul/2022:16:59:02 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" show less
Hacking
Bad Web Bot
Web App Attack
mdmck
02 Jul 2022
20.111.48.39 - - [02/Jul/2022:11:19:01 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 5 ... show more 20.111.48.39 - - [02/Jul/2022:11:19:01 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
20.111.48.39 - - [02/Jul/2022:11:19:01 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
20.111.48.39 - - [02/Jul/2022:11:19:02 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" show less
Web App Attack
Hirte
02 Jul 2022
C1: Web Attack GET /wp-includes/wlwmanifest.xml
Web Spam
Hacking
Bad Web Bot
Web App Attack
mnsf
02 Jul 2022
Too many Status 50X (17)
Brute-Force
Web App Attack
MageHost.pro
02 Jul 2022
11 attempts against mh-misc-ban on guava
Web App Attack
MageHost.pro
02 Jul 2022
10 attempts against mh-misc-ban on guava
Web App Attack
jasperedv.de
01 Jul 2022
Apache Login - Brutforcing
Brute-Force
Web App Attack
iNetWorker
01 Jul 2022
trolling for resource vulnerabilities
Web App Attack
PlexLads
01 Jul 2022
20.111.48.39 - - [01/Jul/2022:19:50:12 -0700] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "- ... show more 20.111.48.39 - - [01/Jul/2022:19:50:12 -0700] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" 20.111.48.39 - - [01/Jul/2022:19:50:13 -0700] "GET /xmlrpc.php?rsd HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" 20.111.48.39 - - [01/Jul/2022:19:50:13 -0700] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" 20.111.48.39 - - [01/Jul/2022:19:50:13 -0700] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" 20.111.48.39 - - [01/Jul/2022:19:50:13 -0700] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Apple
... show less
Hacking
Web App Attack
webstracthosting.com
01 Jul 2022
(wordpress) Failed wordpress login from 20.111.48.39 (FR/France/-)
Brute-Force
zynex
01 Jul 2022
URL Probing: /site/wp-includes/wlwmanifest.xml
Web App Attack
Guardian
01 Jul 2022
Unauthorized connection attempt / Port scanning (x15)
20.111.48.39 [01/Jul/2022:18:39:48] "GET ... show more Unauthorized connection attempt / Port scanning (x15)
20.111.48.39 [01/Jul/2022:18:39:48] "GET / HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //xmlrpc.php?rsd HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET / HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //news/wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2022:18:39:48] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1"
20.111.48.39 [01/Jul/2 show less
Port Scan
Web App Attack