Skip to content

Image: uzcert.uz · rights & removal

Executive Summary

A malicious program named SC possesses the ability to restore deleted malicious files on WordPress sites by utilizing multiple persistence mechanisms across various system locations. The program achieves this restoration through a chain reaction where deleting one component triggers another to recreate it, leading to full restoration. Attackers utilize several hidden locations for components, including site files, the database, server memory, and specific plugin directories like wp-content/plugins and wp-content/mu-plugins. A critical mechanism involves modifying the .user.ini file with an autoprependfile directive, which allows malicious code to execute before WordPress initialization, potentially bypassing standard detection methods. Furthermore, the program stores full copies of its code in the database, shared memory, and dynamically recreates files within theme functions to ensure persistence even after individual deletions. The threat extends beyond simple file removal to include hiding itself from administrative views and targeting administrator sessions, utilizing blockchain infrastructure for command and control communication.

Facts Only

* A malicious program named SC restores deleted malicious files within seconds.
* The restoration occurs by placing parts in various locations like site files, the database, and server memory.
* Deleting a single file is insufficient to remove the infection due to mutually linked persistence mechanisms.
* Malicious components are placed in at least eight different locations allowing for self-restoration.
* The program uses the .user.ini file and autoprependfile directive to load code before PHP execution, potentially bypassing WordPress startup.
* Malicious plugins can exist simultaneously in wp-content/plugins and wp-content/mu-plugins.
* Full copies of malicious code are stored in the database in gzip + Base64 format under unknown names.
* The program uses System V shared-memory to store code outside disk files, persisting data even after file deletion.
* Malicious code is added to functions.php within active theme files as a restoration mechanism.
* The program can hide itself from the WordPress control panel plugin list and modify user rights in the database.
* Command and control infrastructure uses approximately 20 public Ethereum RPC gateway addresses.

Full Take

The narrative highlights that modern persistence mechanisms often rely on systemic entanglement rather than single points of failure, challenging the conventional security paradigm centered on file deletion. The SC program exemplifies a shift from static malware infections to dynamic, adaptive systems where system states themselves become vectors for attack and recovery. The core implication is that defensive strategies focused narrowly on file system scanning fail when the underlying operational context—including database structures, memory states, and execution flows (like PHP pre-loading)—is compromised. The complexity introduced by using shared memory and blockchain channels to command reinforces a systemic view of compromise, suggesting that security must be holistic rather than localized to specific directories. This structure suggests an attacker prioritizing resilience against known remediation tactics, aiming for recovery success regardless of intermediate cleanup efforts. What is being obscured is the reliance on interconnectedness as a feature, not a bug, in system design. How does this dependence on layered persistence affect trust models when administrators operate under the assumption that deleting a file resolves the threat?

From the original · Uzbekistan UZCERT Incidents

ATTENTION! The deleted malicious program on WordPress sites is being restored in a few seconds!
Read the full story at uzcert.uz

Sentinel — Human

Confidence

The text presents a deep, structured analysis of a specific malware persistence technique within WordPress environments, exhibiting high technical specificity consistent with expert reporting rather than general synthetic output.

Signals Detected
low severity: Moderate sentence length variance; consistent use of technical terminology without excessive hedging.
low severity: High internal coherence; the analysis flows logically from describing an attack vector to detailing persistence mechanisms and remediation steps.
medium severity: Structured, enumerated presentation of findings (e.g., list of IoC indicators), suggesting source-based synthesis rather than pure generation.
low severity: Specific, detailed technical claims (e.g., .user.ini, specific plugin locations, blockchain links) suggest reliance on detailed, specialized knowledge which is common in human-authored reports.
Human Indicators
Use of highly specific, deep-dive technical forensic details (e.g., System V shared memory, specific file paths, database artifact descriptions) often found in detailed security analysis by human experts.
The tone shifts effectively between forensic reporting and prescriptive advice, characteristic of specialized journalism or security documentation.
ATTENTION! The deleted malicious software on WordPress sites is being restored in a few seconds! | Huntaegis