This site uses cookies in accordance with our Privacy Policy.
A weekly report of noteworthy threat data by the Defiant threat intelligence team.
Google has removed a Chrome extension from the official Web Store yesterday for secretly hijacking search engine queries and redirecting users to ad-infested search results.
Read More
Verizon sent a big chunk of the internet down a black hole this morning – and caused outages at Cloudflare, Facebook, Amazon, and others – after it wrongly accepted a network misconfiguration from a small ISP in Pennsylvania, USA.
Read More
Hackers believed to be backed by China’s government have infiltrated the cellular networks of at least 10 global carriers, swiping users’ whereabouts, text-messaging records and call logs, according to a new report, amid growing scrutiny of Beijing’s cyberoffensives.
Read More
Name: ConvertPlus <= 3.4.4 - Multiple Issues
Description: Certain configurations allow users to be created with the broken user role of “None”.
Type: A5 – Broken Access Control
Malware samples identified on the greatest count of newly infected sites.
MD5 | Signature | Description | File Names |
---|---|---|---|
C62180F0D626D92E29E83778605DD8BE | Suspicious:PHP/eval_exit.92 | Obfuscated PHP backdoor. | Various .php names like sq.php and wp-cache.php |
048648D9755220E727E7E0178837F7BF | Backdoor:PHP/561C.110 | Obfuscated PHP backdoor | amp3.php, sib.php, wpfunck.php |
1FDB3383EE4D2217C480EDFF309CCA38 | Backdoor:PHP/WSOShell.255 | Slightly customized WSO webshell. | index.php, e2.php, e8.php |
8C9E8184A1523C7286FC11E7DE2EAC55 | Backdoor:PHP/LD_PRELOAD.4426 | PHP script which generates and executes a malicious binary. | wp_form7.php |
C2CC3D90B67A9D6C7DF738A8CD8661C7 | Suspicious:PHP/eval_exit.92 | Obfuscated PHP backdoor. | Generated names consisting of words and 3-digit numerals like 416.conflicts.php, processor.501.php, accepted.client.php, etc. |
Rank | Prev. | IP Address | ASN | Country |
---|---|---|---|---|
1 | 3 | 46.105.99.163 | 16276 (OVH SAS) | FR |
2 | 2 | 46.105.99.212 | 16276 (OVH SAS) | FR |
3 | 4 | 46.105.127.166 | 16276 (OVH SAS) | FR |
4 | 5 | 120.92.88.152 | 59019 (Beijing Kingsoft Cloud Internet Technology Co., Ltd) | CN |
5 | — | 5.8.47.2 | 50896 (Trusov Ilya Igorevych) | PL |
6 | — | 185.238.1.175 | 200313 (Internet It Company Inc) | NL |
7 | — | 162.241.200.136 | 46606 (Unified Layer) | US |
8 | — | 91.121.54.71 | 16276 (OVH SAS) | FR |
9 | — | 139.99.220.144 | 16276 (OVH SAS) | AU |
10 | 8 | 185.225.16.152 | 39798 (MivoCloud SRL) | RO |