🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://bilininimail.com/goreceiver.

Database Entry


IOC ID:1923493
IOC: http://bilininimail.com/goreceiver
IOC Type :url
Threat Type :botnet_cc
Malware: Unknown Stealer
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
First seen:2026-09-18 05:05:34 UTC
Last seen:never
UUID:56c5a07e-b2d8-11f1-8450-42010aa4000a
Reporter ampersand
Reward 5 credits from ThreatFox
Tags:credential-stealer CVE-2026-76581 fake-wordfence mu-plugin WordPress
Reference: https://threatfox.abuse.ch/ioc/1892305/

Avatar
ampersand
Exfiltration endpoint of a fake WordPress must-use plugin posing as "Wordfence Security Core 7.11.5" (file: wp-content/mu-plugins/wordfence-security.php, SHA-256 a4b27bafea5e922b7c291be3961698d4621aec6c13fd6c05e346efafc94ffec0). It hooks wp_authenticate to capture plaintext passwords and POSTs base64-encoded username/password plus request headers and $_SERVER to this URL (endpoint stored as reversed base64: cmV2aWVjZXJvZy9tb2MubGlhbWluaW5pbGliLy86cHR0aA==). The same file contains a second backdoor: GET ?pages_id=<token> grants a first-administrator session when sha1(md5(base64(token))) equals 78786e49d097f38216de24552b0aa7fb7c27fa76. Observed on a Swiss WordPress multisite on 2026-08-26, dropped by a self-deleting plugin "Site Health Monitor 1.2.0" after exploitation of CVE-2026-76581 (WPMU DEV Dashboard Hub SSO authentication bypass). Related IOC: ifuqpatr.com (ThreatFox 1892305), used as the email domain of the covert admin account created by the same dropper.