Virus
-
Unwanted files were placed in the home directory of this plugin.
I have several protection plugins installed, and everything is up-to-date, yet I find a.php, b.php, etc in this plugin’s folder, making me suspect that a weakness exists in this plugin.The hacker’s access (From Ukraine):
(our IP and domain names changed)error log:
proxy_error_log:2017/06/12 09:51:29 [error] 3248#0: *335 connect() failed (111: Connection refused) while connecting to upstream, client: 91.200.14.147, server: XXX.com.tr, request: “POST /wp-content/plugins/easyrotator-for-wordpress/b.php HTTP/1.1”, upstream: “https://xxx.x.xxx.xxx:7080/wp-content/plugins/easyrotator-for-wordpress/b.php”, host: “XXX.com.tr”access log:
access_log.processed.1:91.200.14.147 – – [11/Jun/2017:09:06:15 +0300] “POST /wp-content/plugins/easyrotator-for-wordpress/b.php HTTP/1.0” 200 296 “-” “Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.110 Safari/537.36”
access_log.processed.1:91.200.14.147 – – [11/Jun/2017:09:06:15 +0300] “POST /wp-content/plugins/easyrotator-for-wordpress/b.php HTTP/1.0” 200 259 “-” “Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0”
- The topic ‘Virus’ is closed to new replies.