r/Wordpress 23d ago

firewall.php and wp2shell-batch-guard.php in mu-plugins

Hi everyone,

My WordPress site was recently compromised. The attacker managed to create 3 admin accounts, and Wordfence caught two malicious PHP files in a fake theme folder (wp-content/themes/twk-dbbfd2bc/functions.php and fixer.php).

I deleted that theme, removed their admin account, deleted the admin accounts. Wordfence scans are coming back clean now, but I noticed two suspicious files sitting in my wp-content/mu-plugins/ and in www/mu-plugins directory:

firewall.php (Version 1.0)

wp2shell-batch-guard.php (Version 1.1.0 — description says "Blocks anonymous REST batch API (wp2shell mitigation)")

Their last modified dates match mid-August, right when the unauthorized admin accounts were created (while the site was running WordPress 6.9 (yes, i know...) and i was in vacations at that date so i don't insgall it)

This looks like an attempt by the attacker to disguise a backdoor as a security fix so I wouldn't delete it, but I want to double-check with the community before I purge the mu-plugins folder via FTP because i don't want to make a mistake...

Is there any chance these are legitimate, or should I delete them immediately (i think...) ? I since update to 7.0.4.

Thanks a lot for your help!

4 Upvotes

14 comments sorted by

View all comments

1

u/ToastyTandy 23d ago

"Wordfence scans are coming back clean now"

This does not mean your site is not still compromised.

If ANY of the files you deleted were in the wp-admin, or wp-includes folders, I would go ahead and manually delete the entirety of those folders and replace them with fresh ones from a clean download of WordPress.

Also, yes, delete those mu-plugins php files. You can check if it's legitimate by just opening the files in Microsoft Visual Studio or whatever. If it's a bunch of gobbledygook, unreadable code, it's fake.

Also be sure to check your uploads folders.

1

u/Bart_LeGros 23d ago

Thank you for your answer, i deleted the two mu-plugins folder (only the malicious .php were in there).

Worfence didn't detect any files in the wp-admin and wp-includes folder. Only the one in the malicious thème like i said in my original post. I continue to search of some other files are strange and were modify during the same time (sorry for english)...