Wordfence Weekly September 11 2019 – September 17 2019

A weekly report of noteworthy threat data by the Defiant threat intelligence team.

Most Common New Infections

Malware samples identified on the greatest count of newly infected sites.

MD5 Signature Description Example File Names
701CB9E0ACF43569D3C539B073DAAF2F Spam:PHP/oclasinsert.5483 SEO spam code injector. wp-tmp.php
CEC9A529B43D84F0A0E3624372CD9C51 Backdoor:PHP/WP-VCD.5409 Infected core file, triggers execution of another malicious script. post.php
75234791B9CA71A16FC8432BE4F6A5D0 Backdoor:PHP/wp-vcd.5476 Backdoor associated with SEO spam injections. wp-vcd.php
380FA777B8C37FB60811E5972391261B Suspicious:PHP/evalB64.4068 WebShellOrb PHP webshell. wp-update.php, ob.php, aw.php, and others.
3F60851C9F7E37C0D8817101D2212C68 Suspicious:PHP/eval_b64.1 Obfuscated PHP backdoor. -h7h0pfixp7.phpP, 01nbgrzyxu.php, 05hyfj1bf8.php, and others.

IPs Attacking Most Sites

Rank Prev. IP Address ASN Country
1 5 91.134.154.170 16276 (OVH SAS) France FR
2 74.208.242.128 8560 (1&1 Internet SE) United States US
3 89.33.8.38 9009 (M247 Ltd) Romania RO
4 165.227.48.147 14061 (DigitalOcean, LLC) United States US
5 3.222.192.215 14618 (Amazon.com, Inc.) United States US
6 47.252.4.36 45102 (Alibaba (US) Technology Co., Ltd.) United States US
7 34.70.205.167 15169 (Google LLC) United States US
8 192.99.38.186 16276 (OVH SAS) Canada CA
9 139.99.106.10 16276 (OVH SAS) Singapore SG
10 159.203.86.82 14061 (DigitalOcean, LLC) United States US

New Tracked Domains

Domain Name Date Added Current Status Notes
ns1.bullgoesdown.com 09/12/2019 Up Associated with malicious redirect campaign.
bullgoesdown.com 09/12/2019 Up Associated with malicious redirect campaign.
nataliehaley.kage-tora.com 09/13/2019 Up Hosting malicious code to be sourced by remote scripts.
top.bodr.net 09/16/2019 Up Referenced by a large number of spam infections.
wildmob.ru 09/16/2019 Up Referenced by a large number of spam infections.

Subscribe To The Wordfence Weekly



Did you enjoy this post? Share it!

Recent Issues

Archive