🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 64c175284dc211529b811795c61ba5b8e5f30d162ea7f15845edae945a6fd9a4.

Database Entry


IOC ID:1929826
IOC: 64c175284dc211529b811795c61ba5b8e5f30d162ea7f15845edae945a6fd9a4
IOC Type :sha256_hash
Threat Type :payload
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-09-23 15:47:48 UTC
Last seen:never
UUID:70e104d9-b762-11f1-abee-42010aa4000a
Reporter Efrain
Reward 5 credits from ThreatFox
Tags:backdoor bytebunk PHP ReverseShell webshell WordPress
Reference: https://www.virustotal.com/gui/file/63de5b3b03e3fb95e4d736ce0bec76e54c5299a0553b310ed3b9f270df841a1e

Avatar
Efrain
PHP webshell, 60468 bytes, self-identifying in its first three lines as "BYTE_BUNK Shell v4.0 - Advanced Bypassable Web Shell", author "BYTE_BUNK", Telegram "@Eagle0799".

Capabilities: OS command execution via a getWorkingFunction() probe that walks system, exec, shell_exec, passthru, popen, proc_open, pcntl_exec and uses whichever the host has not disabled; MySQL access with a database credential form; a raw socket via fsockopen giving reverse-shell capability; and arbitrary file read, write, upload, rename, delete, chmod and directory listing. On load it attempts to clear open_basedir, disable_functions, safe_mode and suhosin.executor.disable_eval, and exposes a "bypass" request parameter offering those techniques by name.

Delivered as the root index.php of a repackaged copy of the legitimate WordPress plugin "Protect Uploads" by Alticreation. The other 22 files in the archive are the genuine plugin and are NOT malicious. The real plugin ships a 26-byte "Silence is golden" stub at that path; here it is 60 KB.

Container archive: sha256 63de5b3b03e3fb95e4d736ce0bec76e54c5299a0553b310ed3b9f270df841a1e (49180 bytes), on VirusTotal since approximately May 2026 as qgkunqm.zip and still 0/63. Note WordPress discards the archive after unpacking, so the archive hash will not be found on a compromised host - the payload hash above is the one to hunt for.

Captured by a WordPress login honeypot on ccbeautystudios.com, 2026-09-23 04:06:27 UTC, uploaded via /wp-admin/update.php?action=upload-plugin by 209.92.184.62 (Colocation America, AS21769). It was never executed.

Distinct from, but delivered by the same operator and the same plugin disguise as, sha256 e8dc6ca549b0aed1513ba3a4285556bca1c237e9608f51623b56ec03813403df ("Dark WEBSOCKET File Manager", submitted 2026-09-22). That one has no command execution; this one does.

YARA rule WEBSHELL_PHP_byte_bunk_shell published on YARAhub.