Forensic Investigation Report: Brilliant Light Power Security Breach
This report compiles the timeline, entry vectors, backdoor accounts, and attack details discovered during the forensic analysis of the security breach on brilliantlightpower.com.
1. Timeline of Key Events
| Date (local PDT) | Time (PDT) | UTC Time | Event Type | Description | Source / Evidence |
| May 10, 2026 | 08:06:54 AM | 15:06:54 | Baseline state | Database Backup May 10: First baseline snapshot showing default plugins active (MainWP Child 6.0.11, Slider 6.7.54). | May 10 Backup |
| May 17, 2026 | 08:49:00 AM | 15:49:00 | Baseline state | Database Backup May 17: All plugins at baseline versions (MainWP Child 6.0.11, Slider 6.7.54). | May 17 Backup |
| May 17-24, 2026 | — | — | Plugin Update | Revolution Slider Updated: Upgraded from 6.7.54 to 6.7.55 (detected by options table diff). | Option revslider-latest-version |
| May 20, 2026 | 08:22:14 PM | May 21 03:22:14 | Core Update | WordPress Core Auto-Updated: Upgraded from 6.9.4 to 7.0 (automated cron log event). | May 24 Backup Changes Log ID 108669 |
| May 24, 2026 | 09:43:32 AM | 16:43:32 | Baseline state | Database Backup May 24: Snapshot showing WordPress 7.0 and Slider 6.7.55 active. | May 24 Backup |
| May 24-31, 2026 | — | — | Plugin Update | MainWP Child & Revolution Slider Updated: MainWP Child upgraded from 6.0.11 to 6.1; Slider upgraded from 6.7.55 to 6.7.56 (detected by options table diff). | Option versions diff |
| May 31, 2026 | 10:22:20 AM | 17:22:20 | Baseline state | Database Backup May 31: Snapshot showing MainWP Child 6.1 and Slider 6.7.56 active. | May 31 Backup |
| May 31-Jun 7, 2026 | — | — | Plugin Update | MainWP Child & Revolution Slider Updated: MainWP Child upgraded from 6.1 to vulnerable version 6.1.1; Slider upgraded from 6.7.56 to 6.7.57 (detected by options table diff). | Option versions diff |
| June 7, 2026 | 11:06:05 AM | 18:06:05 | Baseline state | Database Backup June 7: Snapshot showing MainWP Child 6.1.1 and Slider 6.7.57 active. No wp.admin user exists. | June 7 Backup |
| June 10, 2026 | 12:16:16 PM | 19:16:16 | Vulnerability Exploit | First Backdoor Account (wp.admin): Attacker exploits CVE-2026-27366 remotely via API from IP 104.28.159.169 (Cloudflare VPN). | June 14 Backup (Changes Log ID 135078/135079) |
| June 16, 2026 | 07:03:04 AM | 14:03:04 | Plugin Updates | Multiple Plugins Upgraded: Paul Raybould manually upgrades 5 active plugins. | June 16 Backup (Log IDs 142783-142794) |
| June 21, 2026 | 05:10:45 AM | 12:10:45 | Reconnaissance | Attacker Login (IP 1): Attacker logs in as wp.admin from a Cloudflare Warp VPN. | June 23 Backup (yblp_mainwp_child_changes_logs Log ID 149662) |
| June 21, 2026 | 06:01:07 AM | 13:01:07 | Reconnaissance | Attacker Login (IP 2): Attacker logs in as wp.admin from a US Residential connection. | June 23 Backup (yblp_mainwp_child_changes_logs Log ID 149662) |
| June 21, 2026 | 07:15:05 AM | 14:15:05 | Intrusion Start | Attacker Login (IP 3): Attacker logs in as wp.admin from Finland. | June 23 Backup (yblp_mainwp_child_changes_logs Log ID 149662) |
| June 21, 2026 | 07:15:21 AM | 14:15:21 | Malicious Upload | Plugin Uploaded: Attacker uploads file-manager-for-work2.zip containing file manager wrapper. | June 23 Backup (yblp_mainwp_child_changes_logs Log ID 149663/149665) |
| June 21, 2026 | 07:15:26 AM | 14:15:26 | Malicious Activity | Plugin Activated: Attacker activates the File Manager for Work plugin to access server disk. | June 23 Backup (yblp_mainwp_child_changes_logs Log ID 149667) |
| June 21, 2026 | 07:16:08 AM | 14:16:08 | Persistence Setup | Backdoor Dropped: Attacker writes 00-bootstrap.php directly to wp-content/mu-plugins/ via file manager. | Hostinger File Backup June 21 Backup (00-bootstrap.php mod time) |
| June 21, 2026 | 07:16:09 AM | 14:16:09 | Persistence Setup | Backdoor Auto-Initialization: 00-bootstrap.php runs and registers backup user sys_maint as Administrator. | June 23 Backup (yblp_mainwp_child_changes_logs Log ID 149670) |
| June 21, 2026 | 07:16:33 AM | 14:16:33 | Verification | Site Health Check: Attacker browses to homepage / to verify backdoor integration. | Attacker Access Log http_log_176.124.220.186.tsv |
| June 21, 2026 | 07:16:39 AM | 14:16:39 | Verification | Evasion Triggered: Attacker’s browser requests GET /null due to redirect check failure. | Attacker Access Log http_log_176.124.220.186_error_4xx.tsv |
| June 21, 2026 | 07:17:02 AM | 14:17:02 | Intrusion End | Track Cleanup: Attacker deletes the File Manager for Work plugin to remove trace. | June 23 Backup (yblp_mainwp_child_changes_logs Log ID 149678 range check) |
| June 21, 2026 | 08:20:00 AM | 15:20:00 | Persistence Setup | Theme Modifications: Attacker updates wp-content/themes timestamp to edit theme resources. | Hostinger File Backup June 21 Backup (themes/ folder mod time) |
| June 21, 2026 | 11:39:01 PM | June 22 06:39:01 | Monitoring | Return Visit: Attacker checks the homepage from Finland, triggering GET /null again. | Attacker Access Log http_log_176.124.220.186.tsv |
| June 22, 2026 | 09:41:00 AM | 16:41:00 | Incident Detection | Malware Spotted: Jonathan Pugh detects fake Cloudflare captcha redirection on site. | Email correspondence: Compromised site email |
| June 22, 2026 | 09:52:53 AM | 16:52:53 | Monitoring | Return Visit: Attacker checks site and loads assets, triggering GET /null again. | Attacker Access Log http_log_176.124.220.186.tsv |
| June 24, 2026 | 04:50 AM | 11:50:00 | Cleanup Attempt | System Rollback: Paul rolls back site to June 14 check, deleting 00-bootstrap.php and sys_maint. | Email correspondence: Compromised site email |
| June 24, 2026 | 06:28:19 AM | 13:28:19 | Mitigation / Updates | Rollback Re-updates: Paul Raybould manually re-updates rolled-back plugins and upgrades MainWP Child to patch version 6.1.2. | June 25 Backup (Log IDs 140418-140578) |
| June 24, 2026 | 10:45:49 PM | June 25 05:45:49 | Monitoring | Access Check: Attacker requests wp-login.php to verify if credentials are valid. | Attacker Access Log http_log_176.124.220.186.tsv |
| June 25, 2026 | 02:07:46 AM | 09:07:46 | Monitoring | Return Visit: Attacker returns. No /null requested (confirming backdoor script is inactive). | Attacker Access Log http_log_176.124.220.186.tsv |
| June 25, 2026 | 02:16:00 AM | 09:16:00 | Mitigation | Wordfence Cleanup: Wordfence deletes wp.admin account, blocking credentials. | June 25 Backup (yblp_users table) |
2. Attacker Profile & Backdoors Found
Backdoor 1: Primary Account (wp.admin)
- User ID: 13
- Username: wp.admin
- Email: [email protected] (Warning: .st top-level domain mimics legitimate WordPress domains to bypass visual review)
- Registration Date: June 10, 2026 at 19:16:16 UTC
- Capabilities: administrator (User Level 10)
- Evidence Location: Backup from June 23, 2026 19:59:06 UTC (yblp_users and yblp_usermeta tables)
- Status: Deleted on June 25, 2026 by Wordfence.
Backdoor 2: Persistent Backup Account (sys_maint)
- User ID: 14
- Username: sys_maint
- Email: [email protected]
- Registration Date: June 21, 2026 at 14:16:09 UTC
- Capabilities: administrator (User Level 10)
- Evidence Location: Backup from June 23, 2026 19:59:06 UTC (yblp_users and yblp_usermeta tables)
- Status: Deleted by the June 24 rollback (since it was created after the June 14 restore checkpoint).
Backdoor 3: Automated Bootloader script (00-bootstrap.php)
- File Path: public_html/wp-content/mu-plugins/00-bootstrap.php
- Modification Date: June 21, 2026 at 14:16:09 UTC (7:16:09 AM PDT)
- Evidence Location: Hostinger File Backup June 21, 2026 12:46:00 PDT
- Status: Deleted by the June 24 rollback.
3. Forensic Evidence
A. Vulnerability Vector (MainWP Child Plugin)
The attacker exploited CVE-2026-27366 (vulnerability in MainWP Child plugin versions <= 6.1.1). When unique ID verification was disabled in settings, the plugin permitted passwordless administrative connection authentication.
B. Attacker Activity Logs
Our analysis of the WordPress changes log database table (yblp_mainwp_child_changes_logs) from the compromised snapshots (June 14 Backup and June 23 Backup) recorded the following operations:
- Log ID 135078 & 135079 (June 10 at 12:16:16 PM PDT): Attacker exploits CVE-2026-27366 remotely from IP 104.28.159.169 (Cloudflare VPN) to programmatically register user wp.admin and escalate its capabilities to Administrator.
- Log ID 149663 (June 21 at 07:15:21 AM PDT): Attacker uploads plugin archive file-manager-for-work2.zip.
- Log ID 149665 (June 21 at 07:15:21 AM PDT): Attacker registers the plugin “File Manager for Work” (version 4.2.1, author: “Your Name”).
- Log ID 149667 (June 21 at 07:15:26 AM PDT): Attacker activates file-manager-for-work2/file-manager-for-work2.php.
- Log ID 149670 (June 21 at 07:16:09 AM PDT): Must-Use bootloader 00-bootstrap.php triggers and programmatically registers the persistent user sys_maint.
C. Must-Use Backdoor Loader Analysis (00-bootstrap.php)
We successfully isolated and analyzed the backdoor loader script 00-bootstrap.php (stored at /home/u268178543/forensics/00-bootstrap.php on the server). Because it was placed in wp-content/mu-plugins/, WordPress automatically loaded and executed it on every single page request. The file contains several layers of malicious logic:
- Persistent Administrator Account Creation: The script contains hardcoded hex-encoded credentials for a backup administrator user:
- Username: sys_maint
- Email: [email protected]
- Password: ChangeMe_Str0ng! On every admin_init hook trigger, the script checks if a user associated with the _wp_ip meta key exists. If not, it automatically runs wp_create_user() to recreate the account and escalates its capabilities to administrator. This acts as an “auto-heal” backdoor mechanism if the account is manually deleted.
- Stealth and Hiding Mechanisms: To prevent administrators from noticing the sys_maint user in the WordPress dashboard:
- It hooks into the pre_user_query action and modifies the database query WHERE clause: AND {$wpdb->users}.ID NOT IN ( SELECT user_id FROM {$wpdb->usermeta} WHERE meta_key = ‘_wp_ip’ AND meta_value = ‘1’ ) This filters out the sys_maint user from appearing in the dashboard’s Users list.
- It hooks into the REST API rest_user_query filter to ensure the account cannot be queried or listed via public or private API requests.
- Admin Evasion and Target Filtering: The payload injection function _wp_ip_inject is hooked to wp_head and wp_footer. It checks the environment before serving the script:
- It returns immediately if the requested page is wp-login.php to avoid messing with authentication screens.
- It returns immediately if a user is logged in and has administrative capabilities (current_user_can(‘manage_options’)), meaning logged-in administrators were entirely blind to the redirect script when testing the site.
- Web3-Spoofing Malware Payload: The loader injects a large obfuscated JavaScript block that we decrypted using a Node.js sandbox runner. The payload targets Windows desktop visitors to serve them fake Captcha prompts and clip-stealers. The deobfuscated connection endpoint used by this script is:
- https://bsc-1.node.tnet-drpc.com
- Evasion Strategy: The domain is specifically crafted to mimic Web3/blockchain services (Binance Smart Chain bsc-1, decentralized RPC provider drpc, and testnet tnet) to bypass basic domain name blacklist scanners and look like legitimate cryptomining or blockchain connection calls in network activity logs.
D. HTTP Access Logs & Database Changes Logs Correlation
Our down-to-the-second forensic analysis of the attacker’s web access logs (http_log_176.124.220.186.tsv) and the database audit table (yblp_mainwp_child_changes_logs) revealed several critical findings:
- Precision Execution Speed: The entire intrusion on June 21 took exactly 2 minutes and 7 seconds (from the 07:14:56 load of wp-login.php to the 07:17:02 deletion of the File Manager plugin). Below is the precise, down-to-the-second sequence of user actions extracted by correlating access logs and database audit logs:
- 07:14:56 PDT: Attacker loads the /wp-login.php page.
- 07:15:05 PDT (9 seconds later): Attacker submits the login form (POST /wp-login.php), logging in successfully as wp.admin.
- 07:15:12 PDT (7 seconds later): Attacker clicks and navigates to the Plugins list (/wp-admin/plugins.php).
- 07:15:14 PDT (2 seconds later): Attacker clicks “Add New” (/wp-admin/plugin-install.php).
- 07:15:22 PDT (8 seconds later): Attacker uploads the plugin archive (POST /wp-admin/update.php?action=upload-plugin).
- 07:15:27 PDT (5 seconds later): Attacker opens the new File Manager interface (/wp-admin/admin.php?page=fmfw-file-manager).
- 07:15:28 PDT (1 second later): The File Manager UI initializes, sending its first AJAX request (POST /wp-admin/admin-ajax.php).
- 07:16:08 PDT (40 seconds later): Attacker navigates the File Manager filesystem tree to the wp-content/mu-plugins/ directory and uploads/writes the backdoor loader script 00-bootstrap.php.
- 07:16:09 PDT (1 second later): The next AJAX request sent by the File Manager bootstraps WordPress, automatically running the newly created Must-Use plugin 00-bootstrap.php. The script auto-initializes and programmatically registers the backup user sys_maint as an Administrator.
- 07:16:33 PDT (24 seconds later): Attacker loads the homepage (GET /) in another tab to check if the site is alive or broken.
- 07:16:39 PDT (6 seconds later): Attacker’s browser requests GET /null. This is a signature of their injection script’s admin-evasion code failing to load config values for logged-in admins, throwing a JavaScript error.
- 07:16:59 PDT (20 seconds later): Attacker finishes their last file manager action.
- 07:17:02 PDT (3 seconds later): Attacker deletes the File Manager plugin.
- Reconnaissance Logins without Database Footprint: Before performing the file manager write, the attacker logged in as wp.admin twice on the morning of June 21, shifting through different routes/VPNs:
- 05:10:45 PDT from 104.28.194.5 (Cloudflare Warp / VPN)
- 06:01:07 PDT from 98.122.0.237 (US Residential ISP)
- 07:15:05 PDT from 176.124.220.186 (Finland host, when the files were written) By parsing the database changes logs, we verified that no database changes, settings edits, or plugin installations occurred during the first two sessions. The attacker logged in purely to check if their credentials were still active and scan for active security measures before deploying the payload.
- Forensic Value of the /null Evasion Signature: During the active compromise period (June 21 – June 22), the logs show multiple GET /null (404) requests from the attacker’s IP right after loading the homepage. This was a direct side effect of their obfuscated redirection script: it was configured to return null and return early for logged-in administrators to hide itself. This resulted in a JavaScript error on the admin’s browser, triggering a request to /null. On June 25 (today), the attacker returned twice to check the site (02:07:46 PDT and 02:23:12 PDT), but no /null requests were triggered. This provides definitive behavioral confirmation that the backdoor script has been successfully removed and the front-end JS redirection is completely dead.
4. Data Source Reference
This section details the nature, origin, and decoded timestamps of each evidence file used in this forensic analysis.
Summary Table of Data Sources
| Human-Readable Reference & Date | Local File/Source Path | File Type | Data Origin / Description | Decoded Timestamp / Meaning |
| Email from June 25, 2026 14:00 EDT | BLP website may have been hacked.eml | Local Email File (.eml) | Email export containing discussions and malware reports between the site administrators. | Sent/received on June 25, 2026, at 2:00:47 PM EDT (11:00:47 AM PDT). |
| Backup from May 10, 2026 15:06 UTC | u268178543_wp_brlp.20260510150654.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded from Hostinger hPanel backup manager. | Filename timestamp 20260510150654 represents May 10, 2026, 15:06:54 UTC. |
| Backup from May 17, 2026 15:49 UTC | u268178543_wp_brlp.20260517154900.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded from Hostinger hPanel backup manager. | Filename timestamp 20260517154900 represents May 17, 2026, 15:49:00 UTC. |
| Backup from May 24, 2026 16:43 UTC | u268178543_wp_brlp.20260524164332.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded from Hostinger hPanel backup manager. | Filename timestamp 20260524164332 represents May 24, 2026, 16:43:32 UTC. |
| Backup from May 31, 2026 17:22 UTC | u268178543_wp_brlp.20260531172220.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded from Hostinger hPanel backup manager. | Filename timestamp 20260531172220 represents May 31, 2026, 17:22:20 UTC. |
| Backup from June 7, 2026 18:06 UTC | u268178543_wp_brlp.20260607180605.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded from Hostinger hPanel backup manager. | Filename timestamp 20260607180605 represents June 7, 2026, 18:06:05 UTC. |
| Backup from June 14, 2026 18:47 UTC | u268178543_wp_brlp.20260614184702.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded from Hostinger hPanel backup manager. | Filename timestamp 20260614184702 represents June 14, 2026, 18:47:02 UTC. |
| Backup from June 16, 2026 19:03 UTC | u268178543_wp_brlp.20260616190302.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded from Hostinger hPanel backup manager. | Filename timestamp 20260616190302 represents June 16, 2026, 19:03:02 UTC. |
| Backup from June 23, 2026 19:59 UTC | u268178543_wp_brlp.20260623195906.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded during active compromise period. | Filename timestamp 20260623195906 represents June 23, 2026, 19:59:06 UTC. |
| Backup from June 25, 2026 20:16 UTC | u268178543_wp_brlp.20260625201641.sql.gz | Downloaded SQL Database Backup | Compressed database snapshot downloaded after Wordfence cleanups. | Filename timestamp 20260625201641 represents June 25, 2026, 20:16:41 UTC. |
| Live Dump db_clean.sql | /home/u268178543/forensics/db_clean.sql (live server) | Live Server Database Capture | Raw MySQL dump generated directly on the live server. Actually dumped post-rollback. | Dumped on June 25, 2026, at 18:14 UTC (11:14 AM PDT). |
| Live Dump db_infected.sql | /home/u268178543/forensics/db_infected.sql (live server) | Live Server Database Capture | Raw MySQL dump generated directly on the live server. Actually dumped post-rollback. | Dumped on June 25, 2026, at 18:14 UTC (11:14 AM PDT). |
| Hostinger Backup June 21, 2026 12:46 PDT | Virtual snapshot (Hostinger Backup Manager) | Hostinger Filesystem Backup Snapshot | Automated virtual backup of the site’s directories on Hostinger’s backup servers. | Captured on June 21, 2026, at 12:46:00 PM PDT (7:46:00 PM UTC). |
| Backdoor Loader 00-bootstrap.php | 00-bootstrap.php | Backdoor Loader / PHP Script | The malicious bootstrap file written by the attacker to wp-content/mu-plugins/. | Created/modified on the filesystem on June 21, 2026, at 07:16 PDT. |
| Reconnaissance logs http_log_other.txt | http_log_other.txt | Attacker Login Log File | Access logs capturing the attacker’s pre-intrusion logins using other IP addresses. | Records sessions from 104.28.194.5 and 98.122.0.237 on June 21 at 05:10 and 06:01 PDT. |
Detailed Explanations
- Downloaded SQL Database Backups (.sql.gz files)
- Nature: These files are compressed (gzip) exports of the entire WordPress database (containing tables for posts, options, users, logs, etc.). They are generated automatically by Hostinger’s backup infrastructure.
- Decoding Filenames: The filenames follow the pattern [database_username].[YYYYMMDDHHMMSS].sql.gz.
- E.g., u268178543_wp_brlp.20260607180605.sql.gz is decoded as:
- Year: 2026
- Month: 06 (June)
- Day: 07
- Hour: 18 (6 PM)
- Minute: 06
- Second: 05
- Timezone: UTC (Coordinated Universal Time).
- E.g., u268178543_wp_brlp.20260607180605.sql.gz is decoded as:
- Live Server Database Captures (.sql files)
- Nature: These are uncompressed, raw SQL dumps generated manually on the live production server via command line (mysqldump) for direct inspection.
- Caution: Although named db_clean.sql and db_infected.sql by the user/administrator, forensic analysis shows both dumps were generated on June 25, 2026, after the initial June 24 rollback. Therefore, they are live captures representing the state after rollback but before final Wordfence cleanups.
- Hostinger Filesystem Backup Snapshots
- Nature: These are full virtual file system backups maintained by Hostinger’s servers. They capture all folders, PHP files, plugin scripts, themes, and configuration settings as they existed on the server disk at the time of backup. Individual files or folders are downloaded from them via the hPanel web UI.
- Local Email Files (.eml files)
- Nature: Standard raw email client files containing full text body, attachments, routing headers, and email timestamps. They represent the administrative correspondence discussing the compromise.
- Attacker Reconnaissance Logs (http_log_other.txt)
- Nature: Plain text copy of Hostinger server access logs representing visits from IP addresses other than the primary Finland attack vector.
- Forensic Value: Proves that the wp.admin account was accessed for login validation twice before the payload write, showing VPN and ISP hopping patterns.
Report compiled on June 25, 2026.