#virustotal — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #virustotal, aggregated by home.social.
-
A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…
If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!
I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and https://github.com/ruppde/yara_rules.
tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.
Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09 -
This one node is quite the repeat offender in attacccing as a many year logged attaccc server of exploits.
Fastly DNS GammaGroup FinFisher FinSpy
Attaccc Node Proxy IP : 151.101.3.52#Fastly #DNS
#GamaGroup #FinFisher #FinSpy #AttacccProxyServersRescanned today after 2 months of not being scanned.
#infosec #CALEAMalware #GreyMarketInvestigations #RTDNA #news
-
New #StateSponsoredMalware #ForcedMDM client app #SprintMCMapk module update on #GammaGroup #FinFisher #FinSpy #MobileClientManager
The #ForcedMDM #GooglePlayStore #malware on 01-16-2024
Notice how the #PNGs actually are compressed arrays leading to #malware using a long running #PNGListArray in a Portable Network Graphics file format that the client is able to unpack and call to launch #malware attaccc'd as a client from a #GammaGroupProxyServer administrator
#CALEA software Reveals on #Android12 examples
See screenshots #infosec #RTNDA #SSM™ #StateSponsoredMalware™ #GreyMarketInvestigations #CALEA #ForcedMDM #Malware #CivilRightsAbuse logged from #GooglePlayStore
-
CW: #GammaGroup #FinFisher #FinSpy #Finsky app #MCMClient #Android12
#VirusTotal 👉🎁🖼️🎄⚠️☣️👨🔬👩🔬🧫
https://www.virustotal.com/graph/embed/g35450111aae2421fb2e8d1710c51bc5d11fa4c9a2d10451e92c7eca9a0641820#MCMClient #ForcedMDM #MobileID4apk #StateSponsoredMalware™ #SSM #CALEA
This is a component of #ForcedMDM that forces your client through #ProxyServers for easy #MITM & #WITM 💢☣️💯
-
Adventures in Contacting the Russian FSB https://krebsonsecurity.com/2021/06/adventures-in-contacting-the-russian-fsb/ #FederalSecurityService #TreasuryDepartment #VladislavHorohorin #ALittleSunshine #LanceJames #virustotal #CryptoPro #Unit221B #Yandex #BadB #GOST #fbi #FSB #C#
-
Chronicle, X’s security moonshot, moves to Google Cloud - Google Cloud today announced that Chronicle, the enterprise security company Google’s parent compan... more: http://feedproxy.google.com/~r/Techcrunch/~3/90IGaeBjXwA/ #cloudcomputing #stephengillett #thomaskurian #googlecloud #virustotal #chronicle #companies #computing #security #symantec #google #cloud #ceo #coo #x