Wordfence Weekly October 16 2019 – October 22 2019

A weekly report of noteworthy threat data by the Defiant threat intelligence team.

Notable Vulnerabilities

Name: Fast Velocity Minify <= 2.7.6 - Full Path Disclosure
Description: Authenticated users could access plugin status details which included absolute filepaths.
Type: A3 – Sensitive Data Exposure
Name: Bridge <= 18.2 - Open Redirect
Description: Recommended plugins bundled with the theme featured scripts allowing open redirect.
Type: Other
Name: SyntaxHighlighter Evolved 3.5.0 – Stored XSS
Description: Authenticated users could store XSS payloads as shortcode URLs.
Type: A7 – Cross-Site Scripting (XSS)

Most Common New Infections

Malware samples identified on the greatest count of newly infected sites.

MD5 Signature Description Example File Names
CEC9A529B43D84F0A0E3624372CD9C51 Backdoor:PHP/WP-VCD.5409 Infected core file, triggers execution of another malicious script. post.php
80244EB33E847CB91CBEEEAC599755B4 Backdoor:PHP/wp-vcd.5476 Backdoor associated with SEO spam injections. wp-vcd.php
25E947452BCA508802A88DA8D5E197F3 Backdoor:PHP/fileremoval.6373 Self-deleting script associated with malware infections. oihfoe09fposf.php
7D9A88B33CD777B0949A3033512C1D08 Backdoor:PHP/wp-vcd.5476 Backdoor associated with SEO spam injections. wp-vcd.php
380FA777B8C37FB60811E5972391261B Suspicious:PHP/eval_b64.1 WebShellOrb PHP webshell .colors-rtl.php, .lapan.php, .wp-cli.php, and others.

IPs Attacking Most Sites

Rank Prev. IP Address ASN Country
1 5 193.42.118.91 9002 (RETN Limited) Russia RU
2 192.99.38.186 16276 (OVH SAS) Canada CA
3 13.72.67.11 8075 (Microsoft Corporation) United States US
4 165.227.48.147 14061 (DigitalOcean, LLC) United States US
5 40.78.51.116 8075 (Microsoft Corporation) United States US
6 68.183.76.157 14061 (DigitalOcean, LLC) Germany DE
7 163.172.7.237 12876 (Online S.a.s.) France FR
8 94.177.240.87 199653 (Aruba SAS) France FR
9 134.209.42.177 14061 (DigitalOcean, LLC) United States US
10 13.90.62.19 8075 (Microsoft Corporation) United States US

New Tracked Domains

Domain Name Date Added Current Status Notes
team.f4ck.net 10/16/2019 Down Referenced in malware samples.
folaqer.icu 10/18/2019 Down Associated with hardcoded redirects.

Subscribe To The Wordfence Weekly



Did you enjoy this post? Share it!

Recent Issues

Archive