WordPress wlwmanifest.xml Scanner for 2026-08-07
Aug 07, 2026
Exploitation
Last Updated: 00:00 UTC
Bulk scanning for /wp-includes/wlwmanifest.xml, the Windows Live Writer manifest present on default WordPress installs. Hitting many hosts in sequence is the fingerprinting stage of a WordPress-targeted campaign that enumerates installs before launching plugin/theme exploits.
MITRE ATT&CK
Tactic: Reconnaissance (TA0043)
Technique: T1595.002 — Active Scanning: Vulnerability Scanning
Observed URIs
Attackers by Country
| United States of America | 4 | 80.0% |
| United Kingdom of Great Britain and Northern Ireland | 1 | 20.0% |
IP Address : ASN : City/Provider
-
149.102.230.138 : AS174 cogent communications : United States of America
-
149.88.19.91 : AS7922 comcast : New York
-
34.169.78.185 : AS396982 google : United States of America
-
38.253.224.33 : AS174 cogent communications : United States of America
-
85.204.70.104 : ASNone : London
-
91.239.157.185 : unknown : unknown