This site uses cookies in accordance with our Privacy Policy.
A weekly report of noteworthy threat data by the Defiant threat intelligence team.
Malware samples identified on the greatest count of newly infected sites.
MD5 | Signature | Description | Example File Names |
---|---|---|---|
CEC9A529B43D84F0A0E3624372CD9C51 | Backdoor:PHP/WP-VCD.5409 | Infected core file, triggers execution of another malicious script. | post.php |
620C296D324E5825089EC1A46862AB8B | Backdoor:PHP/wp-vcd.5476 | Backdoor associated with SEO spam injections. | wp-vcd.php |
87A7E0017D5672E441F5F9A717A52CC8 | Spam:PHP/WP-VCD.5483 | Backdoor associated with SEO spam injections. | wp-tmp.php |
80244EB33E847CB91CBEEEAC599755B4 | Backdoor:PHP/wp-vcd.5476 | Backdoor associated with SEO spam injections. | wp-vcd.php |
380FA777B8C37FB60811E5972391261B | Suspicious:PHP/eval_b64.1 | WebShellOrb PHP webshell | .colors-rtl.php, .lapan.php, .wp-cli.php, and others. |
Rank | Prev. | IP Address | ASN | Country |
---|---|---|---|---|
1 | — | 51.68.212.47 | 16276 (OVH SAS) | GB |
2 | — | 66.70.236.161 | 16276 (OVH SAS) | CA |
3 | — | 193.42.118.91 | 9002 (RETN Limited) | RU |
4 | — | 193.106.30.99 | 50297 (Infium, UAB) | UA |
5 | — | 40.74.78.92 | 8075 (Microsoft Corporation) | JP |
6 | — | 66.235.169.51 | 40244 (Turnkey Internet Inc.) | US |
7 | — | 103.45.173.26 | 134762 (CHINANET Sichuan province Chengdu MAN network) | CN |
8 | 5 | 40.78.51.116 | 8075 (Microsoft Corporation) | US |
9 | — | 59.56.229.42 | 4134 (No.31,Jin-rong Street) | CN |
10 | — | 109.169.64.234 | 20860 (Iomart Cloud Services Limited) | GB |
Domain Name | Date Added | Current Status | Notes |
---|---|---|---|
top.beforwardplay.com | 10/30/2019 | Up | Referenced in malware samples. |
mypharmwebmart.su | 11/042019 | Up | Associated with hardcoded redirects. |