One of my client who has a website is now seeing hits in their logs for wp-inorms.php from visitors in the Netherlands. Since “wp-” is in the file name, it usually means that the file is apart of WordPress and one would believe that someone and their botnet is out to wreak on the site but this appears to be a trick to end up in the server’s logs (ie. awstats, webalizer) as it often creates free backlinks to the exploiters.
So far, I have not found and files calle wp-inorms.php or wp-insorsm.php on server in any folder so it does appear they are attempting to gain backlinks through referral spam.