How to Detect WebShell?

YuanJiawj

Level 12
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Oct 9, 2014
579
3,159
1,069
37
Unknown
Hi everyone! these days on a VPS with Linux i discovered a Webshell. i've used Linux Malware Detect and has not found any threat, i reviewed my files and I found several files encoded using .base64. there any way to detect files encoded using base64?

Captura.png


Thanks!
 
Hi everyone! these days on a VPS with Linux i discovered a Webshell. i've used Linux Malware Detect and has not found any threat, i reviewed my files and I found several files encoded using .base64. there any way to detect files encoded using base64?

Captura.png


Thanks!
Have you tried this ?

GitHub - emposha/PHP-Shell-Detector: Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%.
 
@Klipsh I've used this tool but the file is not detected. I tried it on localhost and on my VPS and the file is not detected . It is difficult to find file by file manully, I think because this file is encoded :(
 
  • Like
Reactions: LabZero