Local reference
Suspicious dependency
Inferred
Objectives
suspicious severity, 85% confident.
credential-access/phishing
PHP script writing POST data to local file
suspicious severity, 85% confident.
evasion
Target /etc/crontab system crontab
suspicious severity, 95% confident.
execution/interpreter/eval
eval of file_get_contents result
notable severity, 85% confident.
command-and-control/backdoor/webshell
Ignores client abort (webshell indicator)
notable severity, 80% confident.
evasion/masquerade
base64-encode HTTP POST request body
notable severity, 80% confident.
exfiltration
curl -X POST flag
Micro-behaviors
notable severity, 85% confident.
communications/http/request
HTTP REQUEST parameter access ($_REQUEST)
notable severity, 90% confident.
communications/socket
nc command invocation
notable severity, 100% confident.
data/encode
Long continuous hexadecimal string (>64 chars)
notable severity, 85% confident.
fs/write
Move uploaded file to destination
notable severity, 95% confident.
os
Disables error reporting (error_reporting(0))
notable severity, 90% confident.
os/network
ifconfig command
notable severity, 90% confident.
os/privilege
/etc/shadow password file access
notable severity, 95% confident.
process/create/shell
Shell command execution via exec()
Metadata
notable severity, 90% confident.
encoded-payload
Encoded payload detected: base64
Third-party
hostile severity, 90% confident.
SigBase/EXT/WEBSHELL/PHP
php webshell having some kind of input and some kind of payload. restricted to small files or big ones including suspicious strings
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP
PHP webshell which directly eval()s obfuscated string
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Base64/Encoded
php webshell containing base64 encoded payload
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Dynamic
PHP webshell using $a($code) for kind of eval with encoded blob to decode, e.g. b374k
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Generic
php webshell having some kind of input and using a callback to execute the payload. restricted to small files or would give lots of false positives
20 of 47 traits shown
Identity
| SHA-256 | 2fb7e5a2706d99e11b402fdc3970c4ad4e7b863e0f970471c3b3242973d5fc8b |
|---|---|
| Filename | yaps.php |
Origin
| Source | harvest |
|---|---|
| Feed | datasets |
| Ecosystem | webshell |
Timeline
| First seen | 24 Apr 2026 16:15 UTC |
|---|---|
| Last analyzed | 25 Apr 2026 22:48 UTC |
| Last updated | 25 Apr 2026 22:48 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | bf48d |
Not seeing what you expected? Let us know