Local reference
Suspicious dependency
Inferred
Objectives
suspicious severity, 93% confident.
anti-static/obfuscation/encoding
chr(hexdec(...)) custom hex decoder (obfuscation)
suspicious severity, 92% confident.
command-and-control/channel/tunnel
GOST proxy tunneling tool
suspicious severity, 85% confident.
credential-access/phishing
PHP script writing POST data to local file
suspicious severity, 100% confident.
evasion/self-delete
Recursive directory deletion in PHP (self-delete)
suspicious severity, 90% confident.
execution/interpreter/eval
Error-suppressed eval (@eval)
suspicious severity, 92% confident.
impact/infect
Detects delete-and-recreate file pattern
notable severity, 90% confident.
anti-static/obfuscation
Single very long line (webshell
notable severity, 100% confident.
evasion
Checks if exec functions exist
Micro-behaviors
suspicious severity, 93% confident.
communications/email
MIME email with executable attachment
suspicious severity, 90% confident.
communications/http
SSL certificate verification disabled (security
notable severity, 93% confident.
data/db/conn
PHP MySQLi administration surface
notable severity, 100% confident.
fs/delete
PHP rmdir function symbol
notable severity, 100% confident.
fs/enumerate
PHP scandir function symbol
notable severity, 95% confident.
os
Disables error reporting (error_reporting(0))
notable severity, 100% confident.
process/create
PHP mail() function call
notable severity, 95% confident.
process/create/shell
Shell command execution via exec()
Third-party
hostile severity, 90% confident.
SigBase/EXT/WEBSHELL/PHP
php webshell having some kind of input and some kind of payload. restricted to small files or big ones including suspicious strings
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Dynamic
PHP webshell using $a($code) for kind of eval with encoded blob to decode, e.g. b374k
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/Generic
php webshell having some kind of input and using a callback to execute the payload. restricted to small files or would give lots of false positives
hostile severity, 90% confident.
SigBase/WEBSHELL/PHP/OBFUSC/Encoded/Mixed/Dec/And
PHP webshell obfuscated by encoding of mixed hex and dec
20 of 57 traits shown
Identity
| SHA-256 | 88f4bed46b4e8ba8237edb2374a1bef7a252a01a54836ead82b5c7e989c12411 |
|---|---|
| Filename | asw.php |
Origin
| Source | harvest |
|---|---|
| Feed | datasets |
| Ecosystem | webshell |
Timeline
| First seen | 24 Apr 2026 16:15 UTC |
|---|---|
| Last analyzed | 26 Apr 2026 04:56 UTC |
| Last updated | 26 Apr 2026 04:56 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | bf48d |
Not seeing what you expected? Let us know