MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b7ff0262fe7d98cfd1c3ec38cb17d1aa7b66524be8fa2de0ce7a30a3d81fa38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4b7ff0262fe7d98cfd1c3ec38cb17d1aa7b66524be8fa2de0ce7a30a3d81fa38
SHA3-384 hash: c99cb60f09587e0d6211bc5eb320dc8e8d7ec1c6daf684b2e79b6d04ea6f9ab94e927f8b20f9b0c8aea3ffd064a9be9f
SHA1 hash: c12f2993e618a1ae1b9964876facc196221371fb
MD5 hash: e2579f2830672b13fcabaff7564806f9
humanhash: magazine-fish-butter-eighteen
File name:wp-static-cache-fa39743a.php
Download: download sample
File size:1'383 bytes
First seen:2026-07-27 00:19:05 UTC
Last seen:Never
File type:php php
MIME type:text/x-php
ssdeep 24:0wPsgZbEyDaGSg29gCI4hvor/s1+w7w/3seXr+vJqw/IFnXCA:0ksgZXGkzaIkW0eX8TnA
TLSH T12F216A9192CF3D982743249A3D66310B21707A7782FAC6D498FFC656D511D4089BBA3B
Magika php
Reporter aachum
Tags:CVE-2026-60137 CVE-2026-63030 php webshell wordpress wp2shell


Avatar
iamaachum
PHP webshell recovered from a compromised WordPress installation, disguised as a fake plugin named "WP Static Cache Helper" (author spoofed as "WordPress Performance Team").

Believed to be dropped following exploitation of the WordPress core RCE chain publicly known as wp2shell (CVE-2026-60137 SQL injection in WP_Query's author__not_in parameter, chained with CVE-2026-63030 REST API batch-route confusion for unauthenticated access), disclosed 2026-07-17. Attacker created a rogue administrator account, then uploaded these files as a fake plugin.

Intelligence


File Origin
# of uploads :
1
# of downloads :
11
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
backdoor obfuscated obfuscated
Verdict:
Unknown
File Type:
unix shell
First seen:
2026-07-28T19:31:00Z UTC
Last seen:
2026-07-28T21:17:00Z UTC
Hits:
~10
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments