This site uses cookies in accordance with our Privacy Policy.
A weekly report of noteworthy threat data by the Defiant threat intelligence team.
Apple has released a silent update for Mac users removing a vulnerable component in Zoom, the popular video conferencing app, which allowed websites to automatically add a user to a video call without their permission.
Read More
The Facebook-owned photo-sharing service has recently patched a critical vulnerability that could have allowed hackers to compromise any Instagram account without requiring any interaction from the targeted users.
Read More
2020 U.S. presidential campaigns are not using proper email security according to research from Californian-based email threat protection firm Agari.
Read More
Malware samples identified on the greatest count of newly infected sites.
MD5 | Signature | Description | File Names |
---|---|---|---|
C62180F0D626D92E29E83778605DD8BE | Suspicious:PHP/eval_exit.92 | Obfuscated PHP backdoor. | file.php, i.php, ihqxkhi.php, and others. |
C2CC3D90B67A9D6C7DF738A8CD8661C7 | Suspicious:PHP/eval_exit.92 | Obfuscated PHP backdoor. | 101.gone.php, 412.client.php, 423.508.php, and others. |
048648D9755220E727E7E0178837F7BF | Backdoor:PHP/561C.110 | Obfuscated PHP backdoor. | amp3.php, sib.php, wpfunck.php, and others. |
BF3A65A77DA363AC779A2C45FD2DA2FF | Suspicious:PHP/eval_exit.92 | Obfuscated PHP backdoor. | common_config.php |
446ABEFA504998F144A7AE906A173978 | Suspicious:PHP/rot13_of_eval.95 | PHP backdoor which takes XOR-encoded input. | b9448c1c.php |
Rank | Prev. | IP Address | ASN | Country |
---|---|---|---|---|
1 | 7 | 5.8.47.2 | 50896 (Trusov Ilya Igorevych) | PL |
2 | 5 | 120.131.12.178 | 59019 (Beijing Kingsoft Cloud Internet Technology Co., Ltd) | CN |
3 | — | 120.92.33.226 | 23724 (IDC, China Telecommunications Corporation) | CN |
4 | — | 159.69.147.171 | 24940 (Hetzner Online GmbH) | DE |
5 | — | 222.186.46.59 | 23650 (AS Number for CHINANET jiangsu province backbone) | CN |
6 | — | 176.31.123.76 | 16276 (OVH SAS) | FR |
7 | — | 89.46.100.162 | 9009 (M247 Ltd) | RO |
8 | — | 54.37.3.235 | 16276 (OVH SAS) | GB |
9 | — | 82.223.55.105 | 8560 (1&1 Internet SE) | ES |
10 | — | 51.77.53.229 | 16276 (OVH SAS) | PL |
Domain Name | Date Added | Current Status | Notes |
---|---|---|---|
zctrack.com | 07/16/2019 | Up | Ad redirect domain, found injected into theme functions.php files. |
3.bingstyle.com | 07/16/2019 | Up | Associated with zctrack.com infections. |
cdn.blackawardago.com | 07/12/2019 | Up | Referenced in obfuscated malware samples. |
viagranrxfor.org | 07/12/2019 | Up | Pharmaceutical spam domain. |
apps.caresearch.com.au | 07/11/2019 | Up | Hosting JavaScript which is sourced in other injected scripts. |