Part 4 — The Log Lines That Weren’t There

Part 4 of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com By this point I had enough evidence to say: The server had been compromised. I had malicious PHP. I had disguised image files. I had a PHP-based file manager. I had an encoded payload. I had a native executable associated with cryptomining. I had suspicious database activity….

Read More »

Part 3 — I Needed Remote MySQL Access, So I Made It Too Easy

Part 3 of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com There was another problem waiting for me after the filesystem investigation. MySQL. And this one was partly my own fault. I had a legitimate reason for allowing remote MySQL connections. Some of my applications live on temporary cloud VPS instances. I create a VPS when I need…

Read More »

Part 2 — The Files Were Pretending to Be WordPress

Part 2 of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com In Part 1, I stopped the server and started looking at the filesystem instead of immediately trying to get the websites back online. The first confirmed webshell was bf6f03.php. Then I found something more interesting. The attacker had apparently decided that naming a file shell.php was too…

Read More »