Author Topic: Word Press website CMS wrongly installed and spreading malware: emotet - heodo  (Read 1453 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
The error that caused all this:
Quote
SERVER DETAILS
Web Server:
LiteSpeed
X-Powered-By:
PHP/7.3.33
IP Address:
5.22.249.133
Hosting Provider:
CJ2-AS, NL
Shared Hosting:
500 sites found (use Reverse IP to download list)
Title:
WordPress rsaquo; Error

See: https://urlhaus.abuse.ch/url/2118874/
Where detection and malware was missed completely:
https://quttera.com/detailed_report/www.duchessadimotta.com

Where at least the install error testpage was mentioned, but malware not flagged: https://sitecheck.sucuri.net/results/www.duchessadimotta.com/wp-admin/setup-config.php

More sites out there where this was being abused for PHISHING -> https://maltiverse.com/search;query=404testpage4525d2fdc;page=1;sort=creation_time_desc

polonus (volunteer 3rd party cold reconnaissance website security-analyst and website error-hunter)
« Last Edit: March 29, 2022, 02:17:47 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!