Based on the provided information and analysis from Check Point's research report, here are key points about the file structure and components found in compromised WordPress sites:
File Structure of Compromised Websites
-
Malicious Plugin Directory:
- The malicious must-use plugin is installed in a specific directory within the WordPress installation.
- Example path:
/wp-content/plugins/mustuse/
-
Upload Endpoint:
- Threat actors can upload files to infected websites by POSTing to
https://{BASE_URL}/wp-json/wp-sec/v1/upload.
- Threat actors can upload files to infected websites by POSTing to
-
Stolen Data Archives:
- The compromised servers contain directories with data stolen from victims.
- Naming conventions for archives include:
<computer name>documents<number>.zip<computer name>desktop_files<yyyymmdd>_<hhmmss>.zip.encrypted<computer name>pass_V<version><yyyymmdd>_<hhmmss>.zip.encrypted(stolen password files)<computer name>wallet_V<version><yyyymmdd>_<hhmmss>.zip.encrypted(stolen wallet files)
Threat Actor's Self-Infection
- The threat
Read the full article at Check Point Research
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.



