r57shell is a classic server-side web shell, most commonly associated with PHP deployments, that provides attackers with persistent remote control over a compromised web server through an HTTP-accessible interface. It is part of a long-standing family of publicly circulated web shells frequently used after initial compromise to maintain access, execute operating-system commands, manipulate files, and conduct broader post-exploitation activity on internet-facing servers.
The family is widely recognized for exposing administrative capabilities through a browser-based panel. Typical functionality associated with r57shell-class implants includes command execution, directory browsing, file upload and download, file editing, deletion and renaming, permission changes, and general server reconnaissance. In practice, such capabilities make it useful both as a lightweight backdoor and as an operator console for follow-on actions against the host and adjacent application data.
r57shell is primarily relevant to web application and shared-hosting compromises affecting servers that execute PHP or similar server-side content. It is commonly encountered on compromised websites and web servers where attackers have already obtained the ability to place or modify server-side files, whether through exploitation of vulnerable applications, stolen administrative credentials, or abuse of weak deployment hygiene. Once deployed, it serves as a persistence mechanism and post-exploitation foothold rather than a self-propagating intrusion vector.
The malware is best categorized as a webshell because its defining purpose is remote command-and-control via a web interface embedded in server-side code. It is often discussed alongside other well-known web shells such as c99 and PHPSPY, reflecting its role in commodity and opportunistic server intrusions as well as its continued value in hands-on-keyboard operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.