Wordfence Weekly October 09 2019 – October 15 2019

A weekly report of noteworthy threat data by the Defiant threat intelligence team.

Notable Vulnerabilities

Name: WordPress <= 5.2.3 - Multiple Issues
Description: Several vulnerabilities were patched in the latest WordPress release. See link for details.
Type: A7 – Cross-Site Scripting (XSS)

Most Common New Infections

Malware samples identified on the greatest count of newly infected sites.

MD5 Signature Description Example File Names
CEC9A529B43D84F0A0E3624372CD9C51 Backdoor:PHP/WP-VCD.5409 Infected core file, triggers execution of another malicious script. post.php
6AF2FE6DF46DD2BBC5B2FB743117C2A4 Spam:PHP/oclasinsert.5483 SEO spam code injector. wp-tmp.php
7D9A88B33CD777B0949A3033512C1D08 Backdoor:PHP/wp-vcd.5476 Backdoor associated with SEO spam injections. wp-vcd.php
AB5106155B93D614B93086291CA72051 Spam:PHP/oclasinsert.5483 SEO spam code injector. wp-tmp.php
80244EB33E847CB91CBEEEAC599755B4 Backdoor:PHP/wp-vcd.5476 Backdoor associated with SEO spam injections. wp-vcd.php

IPs Attacking Most Sites

Rank Prev. IP Address ASN Country
1 198.27.70.61 16276 (OVH SAS) Canada CA
2 192.99.35.149 16276 (OVH SAS) Canada CA
3 192.99.15.141 16276 (OVH SAS) Canada CA
4 46.105.99.163 16276 (OVH SAS) France FR
5 193.42.118.91 9002 (RETN Limited) Russia RU
6 176.9.71.213 24940 (Hetzner Online GmbH) Germany DE
7 173.236.197.34 26347 (New Dream Network, LLC) United States US
8 120.92.89.35 59019 (Beijing Kingsoft Cloud Internet Technology Co., Ltd) China CN
9 34.66.117.96 15169 (Google LLC) United States US
10 192.99.15.139 16276 (OVH SAS) Canada CA

New Tracked Domains

Domain Name Date Added Current Status Notes
destinywall.org 10/13/2019 Down Hosting malicious javascript sourced by database infections.

Subscribe To The Wordfence Weekly



Did you enjoy this post? Share it!

Recent Issues

Archive