I was wondering whether this was the first actual case where someone exploited vulnerabilities at a wordpress website to place the CIISS v2 proof file on someone else's webserver. To investigate that suspicion I reached out to the Qimam organization (not using the gmail address) the same day these 122 nodes came online.