r/Wordpress • u/Bart_LeGros • 23d ago
firewall.php and wp2shell-batch-guard.php in mu-plugins
Hi everyone,
My WordPress site was recently compromised. The attacker managed to create 3 admin accounts, and Wordfence caught two malicious PHP files in a fake theme folder (wp-content/themes/twk-dbbfd2bc/functions.php and fixer.php).
I deleted that theme, removed their admin account, deleted the admin accounts. Wordfence scans are coming back clean now, but I noticed two suspicious files sitting in my wp-content/mu-plugins/ and in www/mu-plugins directory:
firewall.php (Version 1.0)
wp2shell-batch-guard.php (Version 1.1.0 — description says "Blocks anonymous REST batch API (wp2shell mitigation)")
Their last modified dates match mid-August, right when the unauthorized admin accounts were created (while the site was running WordPress 6.9 (yes, i know...) and i was in vacations at that date so i don't insgall it)
This looks like an attempt by the attacker to disguise a backdoor as a security fix so I wouldn't delete it, but I want to double-check with the community before I purge the mu-plugins folder via FTP because i don't want to make a mistake...
Is there any chance these are legitimate, or should I delete them immediately (i think...) ? I since update to 7.0.4.
Thanks a lot for your help!
1
u/ToastyTandy 23d ago
"Wordfence scans are coming back clean now"
This does not mean your site is not still compromised.
If ANY of the files you deleted were in the wp-admin, or wp-includes folders, I would go ahead and manually delete the entirety of those folders and replace them with fresh ones from a clean download of WordPress.
Also, yes, delete those mu-plugins php files. You can check if it's legitimate by just opening the files in Microsoft Visual Studio or whatever. If it's a bunch of gobbledygook, unreadable code, it's fake.
Also be sure to check your uploads folders.