A DFIR-focused analysis of PHP webshell detection found that hardening servers with PHP disable_functions is not sufficient to stop attackers, because command execution can still be achieved through functions such as popen and proc_open. In lab testing against common implants including p0wny-shell and Weevely, the author showed that publicly available YARA-based detections often identified only a limited subset of samples, leaving other webshells undetected on Linux web servers.
The report recommends combining signature-based scanning with broader forensic and telemetry-driven hunting. It highlights YARA sets such as THOR webshell rules, which target known families including c99, r57, PHPSPY, JspSpy, and WSO, but says defenders should also use manual investigation, file activity timelines, web log frequency analysis, file integrity monitoring, auditd, and EDR process ancestry review to uncover unknown or modified server-side backdoors.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A dfir.ch blog post published a defensive analysis of dangerous PHP functions and Linux webshell hunting, including lab testing of p0wny-shell, Weevely, and simple popen/proc_open shells. The post reported that tested public YARA approaches detected only limited samples and recommended combining tooling with manual investigation and timeline analysis.
The referenced THOR webshell signature set shows that rule webshell_webshell_123 was modified on 2023-01-27, indicating later maintenance of part of the 2014-era ruleset.
Florian Roth of Nextron Systems authored the THOR webshell YARA ruleset used to detect web shells and server-side backdoors across PHP, ASP, JSP, and related technologies. Most rules in the referenced set are dated 2014-01-28 or 2014-03-28.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 771 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.