This site uses cookies in accordance with our Privacy Policy.
A weekly report of noteworthy threat data by the Defiant threat intelligence team.
SIM swapping attacks, where an attacker manages to hijack control of a victim’s phone number, have been used to victimize tens of cryptocurrency users in the US.
Read More
A rapidly-expanding campaign has infected 50,000 servers with malware that mines an open source cryptocurrency called TurtleCoin.
Read More
Name: ConvertPlus <= 3.4.2 – Unauthenticated Arbitrary User Role Creation
Description: Unauthenticated attackers can register new users with administrator permissions when a vulnerable version is active.
Type: A5 – Broken Access Control
Malware samples identified on the greatest count of unique sites.
MD5 | Signature | Description | File Names |
---|---|---|---|
C62180F0D626D92E29E83778605DD8BE | Suspicious:PHP/eval_exit.92 | Obfuscated PHP backdoor. | Various .php names like sq.php and wp-cache.php |
14CF24A13ECAF2783B0265088C30AE85 | Suspicious:PHP/botfilter.6413 | Script used by phishing kits to block watchdog | antibots.php, bt.php |
446ABEFA504998F144A7AE906A173978 | Suspicious:PHP/rot13_of_eval.95 | Obfuscated, password-protected PHP backdoor. | Generated .php names like b9448c1c.php |
BF3A65A77DA363AC779A2C45FD2DA2FF | Suspicious:PHP/eval_exit.92 | Obfuscated PHP backdoor. | common_config.php |
048648D9755220E727E7E0178837F7BF | Backdoor:PHP/561C.110 | Obfuscated PHP backdoor | amp3.php, sib.php, wpfunck.php |
Rank | Prev. | IP Address | ASN | Country |
---|---|---|---|---|
1 | 5 | 167.99.91.253 | 14061 (DigitalOcean, LLC) | UK |
2 | 1 | 5.8.47.2 | 50896 (Trusov Ilya Igorevych) | PL |
3 | — | 62.210.157.10 | 12876 (Online S.a.s.) | FR |
4 | — | 51.79.27.185 | 16276 (OVH SAS) | CA |
5 | — | 120.92.88.152 | 59019 (Beijing Kingsoft Cloud Internet Technology Co., Ltd) | CN |
6 | 8 | 144.217.14.124 | 16276 (OVH SAS) | CA |
7 | 3 | 120.92.102.182 | 59019 (Beijing Kingsoft Cloud Internet Technology Co., Ltd) | CN |
8 | — | 198.27.69.176 | 16276 (OVH SAS) | CA |
9 | — | 46.105.102.54 | 16276 (OVH SAS) | FR |
10 | 10 | 91.121.54.71 | 16276 (OVH SAS) | FR |
Domain Name | Date Added | Current Status | Notes |
---|---|---|---|
traveltogandi.com | 05/29/2019 | Up | Serving JS malware from /stats.js |
funysmile102.life | 06/03/2019 | Down as of 06/04/2019 | Associated with spam links. |
css.developmyredflag.top | 06/04/2019 | Down as of 06/04/2019 | Serving JS malware. |