Symptoms
-
The load to the website is highly increased;
-
Many requests came from the specific IP address according to the report at the Plesk > Domains > example.com > Logs page.
-
The accessed files from logs coincide with the most files from the this list:
List of files used for web crawling
/DOMEN.sql.zip
/NAME_DOMEN.sql.zip
/backup.sql.zip
/database.sql.zip
/main.sql
/main.sql.gz
/main.sql.zip
/shop.sql.gz
/shop.sql.zip
/sql.sql.zip
/www.sql
/www.sql.gz
/www.sql.zip
/wwwroot.sql.gz
/dbdump.sql.zip
/dbdump.sql.rar
/dbdump.sql.tar
/dbdump.bak
/uploads.7z
/uploads.tar.gz
/uploads.bz2
/uploads.bak
/upload.zip
/upload.gz
/test.sql
/test.tar
/test.tar.bz2
/test.tgz
/test.bck
/test.bz2
/test.bak
/security.sql
/security.gz
/security.txt
/security.tar.gz
/secret.sql.gz
/password.sql.zip
/password.sql.rar
/password.sql.tar
/password.bck
/password.bz2
/password.bak
/passwords.7z
/passwords.sql
/passwords.rar
/passwords.gz
/passwords.tar.gz
/pass.tar
/pass.txt
/pass.tgz
/pass.gz
/pass.sql.gz
/latest.sql.gz
/latest.sql.zip
/migration.zip
/migration.sql
/migration.rar
/migration.gz
/migration.tar
/migration.txt
/wp.sql.zip
/wp.sql.rar
/wp.sql.tar
/wp.bck
/wp.bz2
/wp.bak
/wordpress.7z
/wordpress.zip
/wordpress.sql
/wordpress.txt
/wordpress.sql.zip
/wordpress.sql.tar
/wordpress.bck
/wordpress.bz2
/wordpress.bak
/blog.tar
/blog.sql.zip
/blog.sql.rar
/blog.bck
/blog.bz2
/blog.bak
/backup.7z
/backup.sql
/backup.gz
/backup.tar
/backup.tgz
/db1.tar.bz2
/db1.tgz
/db1.sql.gz
/db1.sql.rar
/backup(1).gz
/backup(1).txt
/backup(1).tar.gz
/backup(1).tar.bz2
/backup(1).tgz
/backup(1).sql.zip
/backup(1).sql.rar
/backup(1).sql.tar
/backup(1).bz2
/hosting.txt
/hosting.tar.gz
/hosting.tar.bz2
/hosting.tgz
/hosting.gz
/hosting.sql.gz
/hosting.sql.rar
/hosting.bz2
/host.sql.gz
/server.sql
/server.tar.gz
/server.gz
/linux.gz
/linux.bak
/adminer.php
//2015/wp-includes/wlwmanifest.xml
//2016/wp-includes/wlwmanifest.xml
//2017/wp-includes/wlwmanifest.xml
//2018/wp-includes/wlwmanifest.xml
//media/wp-includes/wlwmanifest.xml
//news/wp-includes/wlwmanifest.xml
//shop/wp-includes/wlwmanifest.xml
//sito/wp-includes/wlwmanifest.xml
//test/wp-includes/wlwmanifest.xml
//web/wp-includes/wlwmanifest.xml
//website/wp-includes/wlwmanifest.xml
//wp1/wp-includes/wlwmanifest.xml
//wp2/wp-includes/wlwmanifest.xml
/wordpress3/wp-login.php
/shop.sql
/shop.rar
/application.zip
/base.sql
/base.zip
/bd.sql
/download.zip
/orders.sql
/site.rar
/site.tar
/site.tar.gz
/site.tgz
/site.zip
/1.tgz
/archive.tar
/archive.tar.gz
/archive.tgz
/archive.zip
/backup.tgz
/blog.tgz
/dump.rar
/forum.tar
/forum.tar.gz
/forum.tgz
/forum.zip
/public_html.sql
/public_html.tgz
/shop.tar
/shop.tar.gz
/shop.tgz
/shop.zip
/b/bigdump.php
/bdump.php
/big/bigdump.php
/bigdump.php
/bigdump/bigdump.php
/bigdump1.php
/dump/bigdump.php
/mysql/bigdump.php
/sql/bigdump.php
/portal/wp-login.php
/assets/plugins/jquery-file-upload/server/php/index.php/assets/plugins/jquery-file-upload/server/php/index.php
/assets/plugins/jquery-file-upload/server/php/index.php
/assets/jquery-file-upload/server/php/index.php…