Expert help needed / High server load / WordPress site being attacked

Hello,

I am on dedicated server for a very high end website. The admins noticed a high load on my server. This has been happening around the same time almost every day.

All Plugins are up to date and Theme also.

Seems that there was a suspicious activity going on from below IPs :

`124.195.19.18 – – [19/Dec/2017:02:33:16 -0500] “POST /wp-content/plugins/dzs-videogallery/upload.php HTTP/1.1” 301 281 “-” “Mobile/11.4 (Edubuntu 7.2; ca_ES;)”

35.196.147.33 – – [19/Dec/2017:02:33:24 -0500] “POST /wp-content/plugins/dzs-portfolio/upload.php HTTP/1.1” 301 278 “-” “SeaMonkey/7.9 (Windows 2000 3.4; ar_KW;)”

115.111.0.201 – – [19/Dec/2017:02:33:24 -0500] “POST /wp-content/plugins/dzs-portfolio/admin/upload.php HTTP/1.1” 301 284 “-” “SeaMonkey/7.9 (Windows 2000 3.4; ar_KW;)”

118.193.107.174 – – [19/Dec/2017:02:33:48 -0500] “POST /wp-content/plugins/dzs-videogallery/upload.php HTTP/1.0” 301 281 “-” “SeaMonkey/15.6 (Macintosh 5.5; en;)”

36.67.114.226 – – [19/Dec/2017:02:33:53 -0500] “POST /wp-content/plugins/dzs-portfolio/upload.php HTTP/1.1” 301 278 “-” “SeaMonkey/7.9 (Windows 2000 3.4; ar_KW;)”

101.236.53.150 – – [19/Dec/2017:02:33:53 -0500] “POST /wp-content/plugins/dzs-portfolio/admin/upload.php HTTP/1.1” 301 284 “-” “SeaMonkey/7.9 (Windows 2000 3.4; ar_KW;)”

101.236.58.168 – – [19/Dec/2017:02:38:58 -0500] “POST /wp-content/plugins/dzs-portfolio/admin/upload.php HTTP/1.1” 301 284 “-” “SeaMonkey/7.9 (Windows 2000 3.4; ar_KW;)” `

Most IPs are from India and Indonesia.

I do NOT have a plugin called dzs-portfolio/admin/upload.php

If anyone can help, it would be greatly appreciated

There are various plugins that are used to block IP; You can use them to block IP;

Blocking Ips won’t solve anything. They will come with other ips. I wanted to know if anyone has seen this before and what can be done? Changing wp-admin url would solve it? By reading what I posted above, what do you make of it?

Changing the wp-admin URL will not make a difference. I get a lot of attempts to find the WP login on my sites and they do not use Wordpress.

Probably not much you can do.

Apparently there was another large scale attack on WP sites that started on 18th December.
https://www.wordfence.com/blog/2017/12/aggressive-brute-force-wordpress-attack/ has more details

This topic was automatically closed 91 days after the last reply. New replies are no longer allowed.