Posts

Showing posts from July, 2021

AnonymousFox Website Fraud

Image
Just today, I check our site's access logs via cPanel and surprised that we are constantly receiving GET requests to non-existent files and folders/directories. These files and directories are files and folders of a WordPress Website. AnonymousFox Fraud When I checked our Website Access Logs, I noticed a series of GET requests from IP Address 32.223.67.184 to non-existent files and directories which apparently returns ERROR 404. The request bears the word "anonymousFox.co" which gave me an Idea to what really made these requests. Series of 404 Requests from anonymousFox Somebody or Something is trying to find vulnerable WordPress Plugins from our site, and when it does, then we're compromised. “AnonymousFox” is related to the old exploit of WordPress 5.5 and the plugin “WP File Manager”, however, recent attacks include not only the WP File Manager but also other vulnerable WordPress Plugins. Your Password will be changed, and your Username will be anonymousFox or simp