It Masquerading as a Legitimate Security Plugin that it contains 3 Files and on of the File Folder Contains some Core Files that seems to offer some Extra Future for WordPress. But all the Files Are Completely Fake.
According to Sucuri, Folder Contained all the Files are Hackingtools and one of the Inspect File “class-social-facebook.php” which Appears to be Related to social network and the plugin pretends to be a “Spam Shield”.
This Malicious File(class-social-facebook.php) will help to Disable all the Plugins that have been Already installed with Target Website. This will prevent to Block access to login functions or would detect the hacker’s unauthorized logins.
Another one Files class-term-metabox-formatter.php helps to send the Version of WordPress and class-admin-user-profile.php send the List of WordPress Admin list to the Attacker.
File Name called plugin-header.php will add the Admin User to the installed WordPress Website.
wp-spam-shield-pro.php File Finally Helps to Connect with Attacker Command & Control Server Later its will share the data includes user, password, infected site URL, and server IP address.
Not all security plugins are secure. By installing fake plugins from unreliable sources or leaving your site vulnerable to compromise, you’re putting your website at a great risk. Descriptions and names can be deceiving, and don’t necessarily mean the plugin will behave in the way that it claims to. Sacuri Said.