s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-bd01d8dfcb86adbaaecf212506e71d5207715f3e92316cda3f7ac41910022217 high

📛 Threat Title

Unknown: created-wp.txt

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: php. Size: 2582 bytes. Tags: account-injection, cpanel, kamp4ng, php, wordpress. Reporter: boredchilada2. First seen: 2026-09-25 03:14:58.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 bd01d8dfcb86adbaaecf212506e71d5207715f3e92316cda3f7ac41910022217

IOC database

Type
hash_sha256
Value
bd01d8dfcb86adbaaecf212506e71d5207715f3e92316cda3f7ac41910022217
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 0408a5e816bb3d0849ca2f20b8993f05a7c66591

IOC database

Type
hash_sha1
Value
0408a5e816bb3d0849ca2f20b8993f05a7c66591
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 90fc465085d2558cda77a87d8b810143

IOC database

Type
hash_md5
Value
90fc465085d2558cda77a87d8b810143
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: php. Size: 2582 bytes. Tags: account-injection, cpanel, kamp4ng, php, wordpress. Reporter: boredchilada2. First seen: 2026-09-25 03:14:58.

Remediations (10)

  • web:brandefense.io

    WP2Shell combines CVE-2026-63030 and CVE-2026-60137 into an unauthenticated WordPress RCE chain. Learn how the exploit works, affected versions, IoCs, detection methods, and mitigation steps.

  • web:clients.websavers.ca

    Check the box beside the core WordPress directory or file that is causing problems (example: wp-admin), then press the "Remove" button. If you're replacing an entire directory, upload the zip file you created , then check the box to the left of your freshly uploaded zip file and press the Extract Files button.

  • web:github.com

    wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation . - ikow/wp2shell

  • web:roihacks.com

    Learn how to identify, isolate, and remove suspicious WordPress files safely while protecting your site from reinfection.

  • web:teisoftllc.com

    The following five-step remediation procedure covers the highest-impact controls against WordPress core vulnerabilities. Each step is executable by a sysadmin without external consulting dependencies.

  • web:threatmon.io

    Analyzing CVE-2026-63030 and CVE-2026-60137 When WordPress quietly pushed emergency security updates on July 17, 2026, it wasn't addressing just another isolated vulnerability. Instead, the patches closed two separate flaws that, when chained together, created something far more serious than either issue on its own. Researchers quickly began referring to the attack chain as wp2shell a ...

  • web:wordpress.org

    False Positive Unknown file in WordPress core Resolved andyexeter (@andyexeter) 1 year, 9 months ago Hey there, On WordPress installs where there WP_CONTENT_DIR is set to the document root, Wordfen…

  • web:wordpress.org

    It's not normally good practice for plugins to create files inside the WordPress core folders, but it can happen with the types of plugin I mentioned above. I'd take the scan's suggestion to remove the file (taking a backup if you wish) and see if it reoccurs in the near future.

  • web:www.ryadel.com

    If suspicious or unknown files are found on your site, it is crucial to act quickly: the longer attackers have access, the more damage they can cause. By following this guide, you can detect and mitigate threats, protecting your WordPress installation and keeping your site secure and operational.

  • web:www.siteguarding.com

    This guide inventories the Top 12 plugin vulnerabilities, explains how attackers exploit them, provides practical detection scripts and checks you can run today, and gives robust mitigation patterns: from vendor patches to virtual patching with a WAF.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.