WordPress sitemiz Phishing saldırısına uğradı. Hosting tarafından iletilen mesaj şu: "Sayın Müşterimiz, İnternet siteniz ile ilgili phishing bildirimi ulaşmıştır, mail üzerinden bilgilendirme yapılmıştır.Kontrol etmenizi rica ederiz."
Hosting firmasından birkaç gün önce Netcraft Takedown Service diye bir firmadan aşağıdaki mail geldi. Site saldırı sonrası kapandı. Dosyalar duruyor. Henüz yedekten geri dönüş yaptırmadım. Hosting firması "zararlı yazılımlar" adlı klasörde toplamış. Konuyla ilgili ücretli profesyonel çözüm verebilecek varsa özelden iletişime geçebilir.
Hello,
Ağınızda bir sızdırma *************** saldırısı (phishing attack) tespit etmiş bulunmaktayız:
hxxp://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/post.php [94.199.200.100]
hxxp://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/login.php?fqfgg= [94.199.200.100]
hxxps://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/post.php [94.199.200.100]
hxxps://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/login.php?email=%7B%7Bemail%7D%7D [94.199.200.100]
We previously contacted you about this issue on 2021-03-11 16:34:27 (UTC).
Since our last notification, the following additional URL(s) have been detected:
hxxp://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/post.php
Bu saldırıdan haberdar olmayabilirsiniz ancak saldırıyı durdurmaktan sorumlusunuz.
Bu saldırı, müşterimiz olan LinkedIn,
https://www.linkedin.com/ web site URLsine sahip müşterimizi hedeflemektedir.
Bu *********** içeriği, ve *********** içerikle ilişkili diğer her şeyi en kısa sürede kaldırmanızı rica ederiz.
Ayrıca, müşterimizin ve kolluk kuvvetlerinin bu olayı site çevirimdışı olduğunda daha ayrıntılı soruşturabilmeleri için, sahte/*********** içeriği lütfen güvende tutunuz.
Daha fazla bilgi için adresi ziyaret ediniz
https://incident.netcraft.com/ea846a1b5e61/
Saygılar,
Netcraft
Phone: +44(0)1225 447500
Fax: +44(0)1225 448600
Netcraft Issue Number: 16192011
Bize bu saldırıyla ilgili edinilen son bilgileri iletmek için lütfen bu e-maile cevap veriniz. Unutmayın ki: bu adrese gelen cevaplar her zaman okunmasa da kaydedilecektir. Bu e-mailin size yanlışlıkla gönderildiğini düşünüyorsanız veya yardıma ihtiyacınız varsa lütfen
takedown@netcraft.com adresinden bize ulaşınız.
Bu e-mail x-arf yardımıyla çözümlenebilir.
http://www.xarf.org/ adresini ziyaret ederek x-arf hakkında daha fazla bilgiye ulaşabilirsiniz.
-------------------
Hello,
We have discovered a phishing attack on your network.
hxxp://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/post.php [94.199.200.100]
hxxp://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/login.php?fqfgg= [94.199.200.100]
hxxps://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/post.php [94.199.200.100]
hxxps://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/login.php?email=%7B%7Bemail%7D%7D [94.199.200.100]
We previously contacted you about this issue on 2021-03-11 16:34:27 (UTC).
Since our last notification, the following additional URL(s) have been detected:
hxxp://fullnet.com[.]tr/gfr/linkedIn.com/linkedIn.com/post.php
You may not have been aware of this attack, however, you are still responsible for removing it.
This attack targets our customer, LinkedIn, website URL
https://www.linkedin.com/.
Please remove this fraudulent content, and any other associated fraudulent content, as soon as possible.
Additionally, please keep the fraudulent content safe so that our customer and law enforcement agencies can investigate this incident further once the site is offline.
More information about the detected issue is provided at
https://incident.netcraft.com/ea846a1b5e61/
Kind regards,
Netcraft
Phone: +44(0)1225 447500
Fax: +44(0)1225 448600
Netcraft Issue Number: 16192011
To contact us about updates regarding this attack, please respond to this email. Please note: replies to this address will be logged, but aren't always read. If you believe you have received this email in error, or you require further support, please contact:
takedown@netcraft.com.
This mail can be parsed with x-arf tools. Visit
http://www.xarf.org/ for more information about x-arf.