TF-1932729
medium
📛 Threat Title
php.shin_webshell: Domain that is used for botnet Command&control (C&C) 5yuj1m1rfv.workers.dev
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 08:24:08 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
5yuj1m1rfv.workers.dev
VT 2 / 91
UrlVoid 2 / 36
IOC database
- Type
- domain
- Value
5yuj1m1rfv.workers.dev- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | CloudFlare, Inc. |
| TLD | workers.dev |
History
| Creation date | 2019-02-08 20:36 UTC |
| Last analysis | 2026-09-25 12:33 UTC |
| Last modified on VirusTotal | 2026-09-25 20:25 UTC |
| Last WHOIS update | 2025-03-10 15:45 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: php.shin_webshell. Confidence: 50. First seen: 2026-09-25 08:24:08 UTC. Reporter: xscon. Tags: Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin.
Remediations (10)
-
web:cybelangel.com
What web shells are, how attackers deploy them, and how defenders find them — including C99 shell analysis and a CISO detection checklist.
-
web:github.com
Common PHP shells is a collection of PHP webshells that you may need for your penetration testing (PT) cases or in a CTF challenge. Do not host any of the files on a publicly-accessible webserver (unless you know what you are up-to).
-
web:safeguard.sh
A PHP webshell gives attackers remote control of a server. Learn how they get planted, what the code looks like, and how to detect and remove one.
-
web:www.microsoft.com
Cookie-gated PHP webshells use obfuscation, php-fpm execution, and cron-based persistence to evade detection in Linux hosting environments. This post examines how this tradecraft conceals execution behind specially crafted HTTP cookies.
-
web:www.threatclaw.ai
Cloudflare Workers, being serverless functions rather than traditional hosting, don't natively execute PHP. When attackers deploy php.shin_webshell to a worker domain , they exploit a different path than the QakBot-style native-C2 model.
-
web:www.threatclaw.ai
EDR / endpoint detections (the real kill-chain anchor): The webshell still needs a victim host to invoke. Monitor for outbound HTTP requests from web servers (IIS/Nginx/Apache workers) to workers.dev endpoints that POST or receive image-content responses. Correlate with the surrounding process (php-cgi, w3wp, httpd) command line and child process spawns.
-
web:www.threatclaw.ai
The Cloudflare Workers Webshell Family ( php.shin_webshell ) Three domains — qhvdg6q2ob.workers.dev, 591jemmy.workers.dev, and the previously-flagged ck.erloro.com pattern — are hosting php.shin_webshell with conf:50-85 and tag Cloudflare,gif,PHP. This is not a coincidence of naming.
-
web:www.threatclaw.ai
QakBot + Shin WebShell on Cloudflare Workers: The Malware-as-a-Service Infrastructure Shift The fresh ThreatFox telemetry surfaces a distinct convergence signal that deserves closer scrutiny than the raw IOC list suggests. Three php.shin_webshell domains — jyjuregu.workers.dev, gotiri.workers.dev, and bohapu.workers.dev (all conf:50, tagged Cloudflare/gif/PHP) — appearing concurrently with ...
-
web:www.threatclaw.ai
The shin_webshell workers.dev cluster is a reminder that infrastructure capability is now a commodity — Cloudflare's free edge has become the attacker's rotating proxy tier, and domain -generation algorithms have migrated from .ru /.top to .workers.dev. Detection must shift from reputation-lookup to behavioral fingerprinting of the TLS edge ...
-
web:www.threatclaw.ai
The shin_webshell Workers Fleet: A Network-Level Blind Spot Worth Closing Today Four domains in the last 24h from ThreatFox all share the same fingerprint: *.workers.dev hosting php.shin_webshell , tagging Cloudflare,gif,PHP. When a legitimate CDN provider is itself the delivery substrate, your traditional URL categorization, domain reputation scoring, and TLS-inspection egress filters all stop ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.