How to Detect WebShell?

YuanJiawj

Level 12
Thread author
Verified
Top Poster
Well-known
Oct 9, 2014
579
Hi everyone! these days on a VPS with Linux i discovered a Webshell. i've used Linux Malware Detect and has not found any threat, i reviewed my files and I found several files encoded using .base64. there any way to detect files encoded using base64?

Captura.png


Thanks!
 
L

LabZero

Hi everyone! these days on a VPS with Linux i discovered a Webshell. i've used Linux Malware Detect and has not found any threat, i reviewed my files and I found several files encoded using .base64. there any way to detect files encoded using base64?

Captura.png


Thanks!
Have you tried this ?

GitHub - emposha/PHP-Shell-Detector: Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%.
 

YuanJiawj

Level 12
Thread author
Verified
Top Poster
Well-known
Oct 9, 2014
579
@Klipsh I've used this tool but the file is not detected. I tried it on localhost and on my VPS and the file is not detected . It is difficult to find file by file manully, I think because this file is encoded :(
 
  • Like
Reactions: LabZero

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top