Forums

wordpress intrusion (2 posts)

  1. huckexp
    Member
    Posted 2 years ago #

    Hello, I noticed on my brand new blog a search from an IP in Russia, the term was
    .com/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser

    He had my exact domain of course in front of it and I traced the IP.
    I was wondering if this was an attempt to hack my new blog or steal paid plugins that I may have stored there.

    His whois info is here if you have problems like this. I will be banning by the IP'S given in the report.

    I hope that this blog less than 24 hours old is not in trouble already with hax.

    Jim

    % Information related to '77.66.208.0 - 77.66.215.255'

    inetnum: 77.66.208.0 - 77.66.215.255
    netname: ROSTOV-GSPD-NET
    descr: IP address space for Rostov-on-Don Regional Data exchange Network
    country: RU
    admin-c: AMK29-RIPE
    tech-c: AAI1-RIPE
    status: ASSIGNED PA
    mnt-by: AS6767-MNT
    remarks: INFRA-AW
    source: RIPE # Filtered

    person: Alexander M Kutsovol
    address: Digital Telephone Lines
    address: 215/3, Stachky av.,
    address: 344091 Rostov-on-Don
    address: Russia
    phone: +7 8632 995263
    phone: +7 8632 994040
    fax-no: +7 8632 994060
    e-mail: Email address protected from spam harvesters
    nic-hdl: AMK29-RIPE
    source: RIPE # Filtered

    person: Alexander A Ivanoff
    address: Digital Telephone Lines
    address: 215/3, Stachky av.,
    address: 344091 Rostov-on-Don
    address: Russia
    phone: +7 8632 995260
    phone: +7 8632 994040
    fax-no: +7 8632 994060
    e-mail: thunder (at) aaanet.ru
    nic-hdl: AAI1-RIPE
    mnt-by: as6767-mnt
    source: RIPE # Filtered

    % Information related to '77.66.128.0/17AS6767'

    route: 77.66.128.0/17
    descr: RU-CTSRND route
    origin: AS6767
    holes: 77.66.192.0/21
    holes: 77.66.200.0/21
    mnt-by: AS6767-MNT
    source: RIPE # Filtered

    % Information related to '77.66.208.0/20AS6767'

    route: 77.66.208.0/20
    descr: RU-CTSRND route
    origin: AS6767
    mnt-by: AS6767-MNT
    source: RIPE # Filtered

  2. huckexp
    Member
    Posted 2 years ago #

    A further investigation shows this ip blacklisted and complaints of spam, phishing and virus email attacks. Typical Russian thieves.

Topic Closed

This topic has been closed to new replies.

About this Topic