We all hear of APT (advanced persistent threat) and this is a good example of one trying to steal the vl.com domain. Very good read:
You May Also Like
Vulnerable WordPress Sites Compromised with Different Database Infections
- January 19, 2023
Vulnerabilities within WordPress can lead to compromise, and oftentimes known vulnerabilities are utilized to infect WordPress sites with more than one infection. It is common…
Xjquery Wave of WordPress SocGholish Injections
- May 9, 2023
In November, 2022, my colleague Ben Martin described how hackers were using zipped files and encrypted WordPress options stored in the database to inject SocGholish…
Why You Should Monitor Your Website
- December 15, 2020
In an effort to maintain unauthorized access or profit off a website’s environment long after an initial compromise, attackers commonly leverage a variety of different…
Fake AmeriCommerce Shopping Cart
- January 23, 2020
Our malware analyst Liam Smith recently found malware on a client’s site that targets ecommerce sites powered by AmeriCommerce software. A popular ecommerce software solution…
How to Get Rid of the Most Common Types of SEO Spam
- February 7, 2022
What is SEO Spam? SEO spam is what attackers will inject into a website to attempt to use your SEO ranking for something else not…
Magento Phishing Leverages JavaScript For Exfiltration
- October 14, 2020
During a recent investigation, a Magento admin login phishing page was found on a compromised website using the file name wp-order.php. This is an odd…
Hackers Change WordPress Siteurl to Pastebin
- November 13, 2018
Last Friday, we reported on a hack that used a vulnerability in the popular WP GDPR Compliance plugin to change WordPress siteurl settings to erealitatea[.]net.…
Trojan Spyware and BEC Attacks
- March 3, 2021
When it comes to an organization’s security, business email compromise (BEC) attacks are a big problem. One primary reason impacts are so significant is that…
Product Update: Sucuri Firewall in Sophia
- December 11, 2019
Sucuri provides security for websites with the protection of our Web Application Firewall (WAF). We also have our proprietary Anycast content delivery network (CDN) that…
Cryptominers: Binary-Process-Cron Variants and Methods of Removal
- August 2, 2018
This post provides a brief overview of how to manually remove server-side cryptominers and other types of Binary-Process-Cron malware from a server. Unlike browser-based JavaScript…








