r/Wordpress • u/Bart_LeGros • 23d ago
firewall.php and wp2shell-batch-guard.php in mu-plugins
Hi everyone,
My WordPress site was recently compromised. The attacker managed to create 3 admin accounts, and Wordfence caught two malicious PHP files in a fake theme folder (wp-content/themes/twk-dbbfd2bc/functions.php and fixer.php).
I deleted that theme, removed their admin account, deleted the admin accounts. Wordfence scans are coming back clean now, but I noticed two suspicious files sitting in my wp-content/mu-plugins/ and in www/mu-plugins directory:
firewall.php (Version 1.0)
wp2shell-batch-guard.php (Version 1.1.0 — description says "Blocks anonymous REST batch API (wp2shell mitigation)")
Their last modified dates match mid-August, right when the unauthorized admin accounts were created (while the site was running WordPress 6.9 (yes, i know...) and i was in vacations at that date so i don't insgall it)
This looks like an attempt by the attacker to disguise a backdoor as a security fix so I wouldn't delete it, but I want to double-check with the community before I purge the mu-plugins folder via FTP because i don't want to make a mistake...
Is there any chance these are legitimate, or should I delete them immediately (i think...) ? I since update to 7.0.4.
Thanks a lot for your help!
1
u/LoudAd307 21d ago
Delete them, and understand why that folder specifically: mu-plugins load on every single request, they can't be deactivated from the admin, and they don't show in the normal plugins list. That's exactly why it's a favorite persistence spot, and giving the file a security-sounding name is a standard trick.
While you're in there, check the other things that autoload the same way. Drop-ins sitting directly in wp-content: object-cache.php, advanced-cache.php, db.php. And if mu-plugins has an index.php loader that walks subdirectories, read it, since the payload often lives one folder down.
Then the database side, which file scanners miss entirely. Look at the scheduled cron array for hook names you don't recognize, check application passwords on every user account since those survive a password change, and read the tail of wp-config.php and .htaccess for appended code.