Part 2 — The Files Were Pretending to Be WordPress
Part 2 of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com In Part 1, I stopped the server and started looking at the filesystem instead of immediately trying to get the websites back online. The first confirmed webshell was bf6f03.php. Then I found something more interesting. The attacker had apparently decided that naming a file shell.php was too…
Read More »