Shell 2012 Ok.ru _best_ Link
The attacker used tools like nmap and wpscan (if ok.ru used WordPress for subdomains) or custom scripts to identify the server software (likely nginx + PHP-FPM).
Before addressing the 2012 and ok.ru components, we must define the term "shell" in this context. shell 2012 ok.ru