ThreatFox IOC Database
You are viewing the ThreatFox database entry for sha256_hash 64c175284dc211529b811795c61ba5b8e5f30d162ea7f15845edae945a6fd9a4.
Database Entry
| IOC ID: | 1929826 |
|---|---|
| IOC: | 64c175284dc211529b811795c61ba5b8e5f30d162ea7f15845edae945a6fd9a4 |
| IOC Type : | sha256_hash |
| Threat Type : | payload |
| Malware: | Unknown malware |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| First seen: | 2026-09-23 15:47:48 UTC |
| Last seen: | never |
| UUID: | 70e104d9-b762-11f1-abee-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | backdoor bytebunk PHP ReverseShell webshell WordPress |
| Reference: | https://www.virustotal.com/gui/file/63de5b3b03e3fb95e4d736ce0bec76e54c5299a0553b310ed3b9f270df841a1e |
Efrain
PHP webshell, 60468 bytes, self-identifying in its first three lines as "BYTE_BUNK Shell v4.0 - Advanced Bypassable Web Shell", author "BYTE_BUNK", Telegram "@Eagle0799".Capabilities: OS command execution via a getWorkingFunction() probe that walks system, exec, shell_exec, passthru, popen, proc_open, pcntl_exec and uses whichever the host has not disabled; MySQL access with a database credential form; a raw socket via fsockopen giving reverse-shell capability; and arbitrary file read, write, upload, rename, delete, chmod and directory listing. On load it attempts to clear open_basedir, disable_functions, safe_mode and suhosin.executor.disable_eval, and exposes a "bypass" request parameter offering those techniques by name.
Delivered as the root index.php of a repackaged copy of the legitimate WordPress plugin "Protect Uploads" by Alticreation. The other 22 files in the archive are the genuine plugin and are NOT malicious. The real plugin ships a 26-byte "Silence is golden" stub at that path; here it is 60 KB.
Container archive: sha256 63de5b3b03e3fb95e4d736ce0bec76e54c5299a0553b310ed3b9f270df841a1e (49180 bytes), on VirusTotal since approximately May 2026 as qgkunqm.zip and still 0/63. Note WordPress discards the archive after unpacking, so the archive hash will not be found on a compromised host - the payload hash above is the one to hunt for.
Captured by a WordPress login honeypot on ccbeautystudios.com, 2026-09-23 04:06:27 UTC, uploaded via /wp-admin/update.php?action=upload-plugin by 209.92.184.62 (Colocation America, AS21769). It was never executed.
Distinct from, but delivered by the same operator and the same plugin disguise as, sha256 e8dc6ca549b0aed1513ba3a4285556bca1c237e9608f51623b56ec03813403df ("Dark WEBSOCKET File Manager", submitted 2026-09-22). That one has no command execution; this one does.
YARA rule WEBSHELL_PHP_byte_bunk_shell published on YARAhub.