I have seen it before in infected WordPress instances related to recent remote RCE. Probably one victim more.