Simplileap logo

// Case study

Malware hidden inside a WordPress favicon.ico

Outbound traffic spikes traced to PHP embedded in a .ico file, full filesystem IOC sweep, credential rotation, and WAF rules restored a clean bill of health in 72 hours.

Professional servicesIncident response & hardening72 hours (active remediation)Bangalore delivery

A mid-size professional services firm in Bangalore experiencing outbound DNS anomalies and crawl-rate drops. Surface security scans returned clean; Simplileap was engaged for deep filesystem forensics and sustained hardening.

72 hours

Remediation window

Outbound anomaly ceased

5 days

Safe Browsing clearance

Google Safe Browsing restored

None detected

Data exfiltration

Retained log analysis

favicon.ico

Payload vector

14KB PHP-in-binary obfuscation

Delivered by Goutham S · Published July 22, 2025 · 9 min read

Client context

A mid-size professional services firm in Bangalore noticed intermittent outbound DNS requests to unknown domains and a sudden crawl-rate drop. Their hosting provider flagged elevated PHP-FPM workers overnight. Wordfence reported "clean" on a surface scan; Sucuri's remote check flagged anomalous response headers on the favicon request.

Delivery notes

Simplileap's first hypothesis was a compromised plugin or wp-config injection, common patterns. grep across wp-content for eval, base64_decode, and gzinflate returned nothing obvious. Access logs showed repeated GET /favicon.ico from the same three IP ranges, each response slightly larger than the stock asset.

On disk, favicon.ico was 14KB instead of the expected 1.2KB. Hex inspection revealed appended PHP after the ICO magic bytes, obfuscated with rot13 and chunked base64 that decoded to a mailer stub and remote command handler. The file timestamp matched a Friday evening when a contractor's FTP credentials were used from a residential ISP in another state.

The challenge

Problems during remediation: restoring from a "clean" backup from 10 days prior reintroduced the payload because the backup job itself ran before detection; two mu-plugins had been added with legitimate-sounding names (wp-cache-helper.php) that re-dropped the payload if favicon.ico was deleted without chmod hardening on uploads.

Our approach

Response playbook: isolate origin behind maintenance mode with allow-listed office IPs; rotate all SFTP, wp-admin, and database credentials; export IOC list (file hashes, mu-plugin paths, rogue cron events); surgical delete and replace favicon from known-good source; full wp-content scan with maldet and custom YARA rules for PHP-in-binary patterns.

Technical implementation

Hardening delivered: disable file editing in wp-config; move wp-admin behind IP allow list + 2FA; immutable S3 backups with cross-region replication; WAF rule blocking PHP execution in uploads and static asset directories; monthly malware scan cadence added to AMC retainer.

Results & impact

Outcome: outbound anomaly ceased within 72 hours; Google Safe Browsing clearance within five days; no evidence of customer data exfiltration in retained logs. The client moved to our Commerce-tier AMC with staging-before-prod plugin policy. Identity withheld under security engagement terms.

← Back to case studies

// Verified entity

Simplileap Digital LLP

// Recognition

Featured in QuickNode Feature Fridays

CIN

AAU-8582

Startup India

DIPP83124

Founded

November 2020

Office

Residency Rd, Bengaluru, India

Ready to scope your next initiative?

Share your goals with our Bangalore team. We respond within one business day with a clear path from discovery to delivery.