This site uses cookies in accordance with our Privacy Policy.
A weekly report of noteworthy threat data by the Defiant threat intelligence team.
Malware samples identified on the greatest count of newly infected sites.
MD5 | Signature | Description | Example File Names |
---|---|---|---|
CEC9A529B43D84F0A0E3624372CD9C51 | Backdoor:PHP/WP-VCD.5409 | Infected core file, triggers execution of another malicious script. | post.php |
80244EB33E847CB91CBEEEAC599755B4 | Backdoor:PHP/wp-vcd.5476 | Backdoor associated with SEO spam injections. | wp-vcd.php |
25E947452BCA508802A88DA8D5E197F3 | Backdoor:PHP/fileremoval.6373 | Self-deleting script associated with malware infections. | oihfoe09fposf.php |
7D9A88B33CD777B0949A3033512C1D08 | Backdoor:PHP/wp-vcd.5476 | Backdoor associated with SEO spam injections. | wp-vcd.php |
380FA777B8C37FB60811E5972391261B | Suspicious:PHP/eval_b64.1 | WebShellOrb PHP webshell | .colors-rtl.php, .lapan.php, .wp-cli.php, and others. |
Rank | Prev. | IP Address | ASN | Country |
---|---|---|---|---|
1 | 5 | 193.42.118.91 | 9002 (RETN Limited) | RU |
2 | — | 192.99.38.186 | 16276 (OVH SAS) | CA |
3 | — | 13.72.67.11 | 8075 (Microsoft Corporation) | US |
4 | — | 165.227.48.147 | 14061 (DigitalOcean, LLC) | US |
5 | — | 40.78.51.116 | 8075 (Microsoft Corporation) | US |
6 | — | 68.183.76.157 | 14061 (DigitalOcean, LLC) | DE |
7 | — | 163.172.7.237 | 12876 (Online S.a.s.) | FR |
8 | — | 94.177.240.87 | 199653 (Aruba SAS) | FR |
9 | — | 134.209.42.177 | 14061 (DigitalOcean, LLC) | US |
10 | — | 13.90.62.19 | 8075 (Microsoft Corporation) | US |
Domain Name | Date Added | Current Status | Notes |
---|---|---|---|
team.f4ck.net | 10/16/2019 | Down | Referenced in malware samples. |
folaqer.icu | 10/18/2019 | Down | Associated with hardcoded redirects. |