MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 de9efd031aef9caed59021a2c79356d875648426a921151e18db33ce75aeacff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: de9efd031aef9caed59021a2c79356d875648426a921151e18db33ce75aeacff
SHA3-384 hash: 4177723df1ed27f2d99f2e4a750a8b3eaf8d20dc659d227d92c0c0ad414680114cdb1769b7fb5b27ff30041f96347d1a
SHA1 hash: 692993f8b0f241eed8cf2636bc7b1ed17c2de3d1
MD5 hash: 77619e60fa9c3a1e9d52b5e43003c523
humanhash: lima-burger-december-queen
File name:wp-static-cache-7c197308.php
Download: download sample
File size:1'361 bytes
First seen:2026-07-27 00:17:50 UTC
Last seen:Never
File type:php php
MIME type:text/x-php
ssdeep 24:0wPsgZbEyDS7dKm+CI4hvoOs1+w7w/3seXr+vJqw/YqzA:0ksgZX2YzawW0eX8TdA
TLSH T14D2167A183CF3E692752259A3CA9310B11307AB782FAC6D098FFC655D511C4089FBA3B
Magika php
Reporter aachum
Tags:CVE-2026-60137 CVE-2026-63030 php webshell wordpress wp2shell


Avatar
iamaachum
PHP webshell recovered from a compromised WordPress installation, disguised as a fake plugin named "WP Static Cache Helper" (author spoofed as "WordPress Performance Team").

Believed to be dropped following exploitation of the WordPress core RCE chain publicly known as wp2shell (CVE-2026-60137 SQL injection in WP_Query's author__not_in parameter, chained with CVE-2026-63030 REST API batch-route confusion for unauthenticated access), disclosed 2026-07-17. Attacker created a rogue administrator account, then uploaded these files as a fake plugin.

Intelligence


File Origin
# of uploads :
1
# of downloads :
16
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated php
Verdict:
Unknown
File Type:
unix shell
First seen:
2026-07-28T19:31:00Z UTC
Last seen:
2026-07-28T21:17:00Z UTC
Hits:
~10
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments